IKE: Cisco DOS
This protocol anomaly is an IKE packet with an Identification payload that is 4 bytes long. Cisco VPN concentrators up to version 3.6.0 are vulnerable to specially formatted IKE packets. Attackers can send an Identification payload with a length of 4 bytes to cause the device to reload itself, causing a denial of service (DoS).
Extended Description
There are a number of circumstances where maliciously constructed Internet Security Association and Key Management Protocol (ISAKMP) packets may cause an affected Cisco VPN 3000 Concentrator device to reload. Denial of network/VPN service may be possible.
Affected Products
Cisco vpn_3000_concentrator,Cisco vpn_3000_concentrator
References
BugTraq: 5619
CVE: CVE-2002-1103
URL: http://www.kb.cert.org/vuls/id/761651 http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtml
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Cisco
5.0