Cisco IOS cTCP Denial of Service Vulnerability - Cisco Systems

This script is (C) 2010-2014 Tenable Network Security, Inc.


Synopsis :

The remote device is missing a vendor-supplied security patch.

Description :

A series of TCP packets may cause a denial of service (DoS) condition
on Cisco IOS devices that are configured as Easy VPN servers with the
Cisco Tunneling Control Protocol (cTCP) encapsulation feature. Cisco
has released free software updates that address this vulnerability. No
workarounds are available
however, the IPSec NAT traversal (NAT-T)
feature can be used as an alternative.

See also :

http://www.nessus.org/u?03cb73c5
http://www.nessus.org/u?148d2178

Solution :

Apply the relevant patch referenced in Cisco Security Advisory
cisco-sa-20090325-ctcp.

Risk factor :

High / CVSS Base Score : 7.8
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS Temporal Score : 6.4
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: CISCO

Nessus Plugin ID: 49029 (cisco-sa-20090325-ctcphttp.nasl)

Bugtraq ID: 34246

CVE ID: CVE-2009-0635

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial