Executive Risk Summary
"A denial of service vulnerability exists in the IKEv1 implementation of Cisco IOS, allowing remote attackers to cause a device reload by sending IKE UDP packets over IPv4 or IPv6. This vulnerability affects Cisco IOS versions 12.2 through 12.4 and 15.0 through 15.2, as well as IOS XE versions 2.1.x through 2.6.x and 3.1.xS through 3.4.xS."
Anticipated Attack Path
- 1. Attacker sends IKE UDP packets over IPv4 or IPv6
- 2. IKEv1 implementation processes the packets, causing a device reload
- 3. Device becomes unavailable, resulting in a denial of service
Am I Vulnerable?
- Verify Cisco IOS version and patch level
- Check for IKEv1 implementation vulnerabilities
- Implement IKEv2 or other secure protocols
Operational Audit Arsenal
Target Type Network Device
Target Asset IKEv1 Process
Standard Path Cisco IOS
Manual Verification Required
This is a non-Windows asset (Cisco). Use the target asset details and official path provided above to verify your current version against the official vendor advisories listed below.
Patch Impact Forecast
Reboot Required Likely
Network connectivity may be disrupted during the patching process
Internal Work Notes
Denial of service vulnerability in Cisco IOS IKEv1 implementation, requiring patching to prevent device reloads
Technical Intelligence & Operational Utilities • Delivered Weekly
Intelligence Sources
Official Advisoryhttp://osvdb.org/80700
Official Advisoryhttp://secunia.com/advisories/48605
Official Advisoryhttp://secunia.com/advisories/48607
Official Advisoryhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-ike
Official Advisoryhttp://www.securityfocus.com/bid/52757
Official Advisoryhttp://www.securitytracker.com/id?1026863
Official Advisoryhttps://exchange.xforce.ibmcloud.com/vulnerabilities/74427
Official Advisoryhttp://osvdb.org/80700
Official Advisoryhttp://secunia.com/advisories/48605
Official Advisoryhttp://secunia.com/advisories/48607
Official Advisoryhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-ike
Official Advisoryhttp://www.securityfocus.com/bid/52757
Official Advisoryhttp://www.securitytracker.com/id?1026863
Official Advisoryhttps://exchange.xforce.ibmcloud.com/vulnerabilities/74427
Related Cisco Threats
Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.