Release date:
Updated on:
Affected Systems:
Cisco IOS 15.x
Cisco IOS 12.2
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-2108
Cisco IOS is an interconnected network operating system used on most Cisco system routers and network switches.
Cisco IOS 12.2, 15.0-15.3, ios xe 3.2-3.7, and 3.8-3.10 have security vulnerabilities. Remote attackers use specially crafted IKEv2 packets, this vulnerability can cause DoS (memory depletion ).
<* Source: vendor
Link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140326-ikev2
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (cisco-sa-20140326-ikev2) and patches for this:
Cisco-sa-20140326-ikev2: Cisco IOS Software Internet Key Exchange Version 2 Denial of Service Vulnerability
Link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140326-ikev2