Vulnerability Name:

CVE-2009-1168 (CCN-52134)

Assigned:2009-07-29
Published:2009-07-29
Updated:2017-09-29
Summary:Cisco IOS 12.0(32)S12 through 12.0(32)S13 and 12.0(33)S3 through 12.0(33)S4, 12.0(32)SY8 through 12.0(32)SY9, 12.2(33)SXI1, 12.2XNC before 12.2(33)XNC2, 12.2XND before 12.2(33)XND1, and 12.4(24)T1; and IOS XE 2.3 through 2.3.1t and 2.4 through 2.4.0; when RFC4893 BGP routing is enabled, allows remote attackers to cause a denial of service (memory corruption and device reload) by using an RFC4271 peer to send an update with a long series of AS numbers, aka Bug ID CSCsy86021.
CVSS v3 Severity:7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:7.1 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C)
5.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
7.1 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-399
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2009-1168

Source: CCN
Type: SA36046
Cisco IOS Border Gateway Protocol Two Denial of Service Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
36046

Source: CCN
Type: SECTRACK ID: 1022619
Cisco IOS 4-Byte ASN Support Bugs in Processing BGP Updates Let Remote Users Deny Service

Source: CISCO
Type: Patch, Vendor Advisory
20090729 Cisco IOS Software Border Gateway Protocol 4-Byte Autonomous System Number Vulnerabilities

Source: CCN
Type: cisco-sa-20090729-bgp
Cisco IOS Software Border Gateway Protocol 4-Byte Autonomous System Number Vulnerabilities

Source: CCN
Type: OSVDB ID: 56704
Cisco IOS Border Gateway Protocol (BGP) Update Malformed AS Path Segment Remote DoS

Source: BID
Type: UNKNOWN
35862

Source: CCN
Type: BID-35862
Cisco IOS Malformed BGP Anonymous System Path Denial of Service Vulnerability

Source: SECTRACK
Type: UNKNOWN
1022619

Source: VUPEN
Type: UNKNOWN
ADV-2009-2082

Source: XF
Type: UNKNOWN
ios-bgp-aspath-dos(52134)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:6697

Vulnerable Configuration:Configuration 1:
  • cpe:/o:cisco:ios:12.0(32)s12:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.0(32)s13:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.0(32)sy8:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.0(32)sy9:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.0(33)s3:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.0(33)s4:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2(33)sxi1:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2(33)sxi2:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2xnc:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2xnd:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.4(24)t1:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios_xe:2.3:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios_xe:2.3.1t:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios_xe:2.4:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios_xe:2.4.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:cisco:ios:12.0(32)s12:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.0(32)s13:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.0(33)s3:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.0(33)s4:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.0(32)sy8:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.0(32)sy9:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2(33)sxi2:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2(33)sxi1:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios_xe:2.3:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios_xe:2.4.0:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios_xe:2.4:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios_xe:2.3.1t:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2xnd:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2xnc:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.4(24)t1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:6697
    V
    Cisco IOS Software BGP Routing Dos Vulnerability
    2013-04-22
    BACK
    cisco ios 12.0(32)s12
    cisco ios 12.0(32)s13
    cisco ios 12.0(32)sy8
    cisco ios 12.0(32)sy9
    cisco ios 12.0(33)s3
    cisco ios 12.0(33)s4
    cisco ios 12.2(33)sxi1
    cisco ios 12.2(33)sxi2
    cisco ios 12.2xnc
    cisco ios 12.2xnd
    cisco ios 12.4(24)t1
    cisco ios xe 2.3
    cisco ios xe 2.3.1t
    cisco ios xe 2.4
    cisco ios xe 2.4.0
    cisco ios 12.0(32)s12
    cisco ios 12.0(32)s13
    cisco ios 12.0(33)s3
    cisco ios 12.0(33)s4
    cisco ios 12.0(32)sy8
    cisco ios 12.0(32)sy9
    cisco ios 12.2(33)sxi2
    cisco ios 12.2(33)sxi1
    cisco ios xe 2.3
    cisco ios xe 2.4.0
    cisco ios xe 2.4
    cisco ios xe 2.3.1t
    cisco ios 12.2xnd
    cisco ios 12.2xnc
    cisco ios 12.4(24)t1