Cisco IOS and IOS XE Software IKEv1 State Machine Denial of Service Vulnerability
The vulnerability is due to insufficient condition checks in the IKEv1 state machine. An attacker could exploit this vulnerability by sending a spoofed, specific IKEv1 packet to an endpoint of an IPsec tunnel. A successful exploit could allow the attacker to tear down IPsec tunnels that terminate on the endpoint, causing a partial DoS condition.
Cisco has released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability.
This advisory is available at the following link: http://ift.tt/1PaYeoF
from Cisco Security Advisory http://ift.tt/1PaYeoF