CVE-2008-2739
Last modified
CVE-2008-2739 is a vulnerability of currently unknown severity. The SERVICE.DNS signature engine in the Intrusion Prevention System (IPS) in Cisco IOS 12.3 and 12.4 allows remote attackers to cause a denial of service (device crash or hang) via network traffic that triggers unspecified IPS signatures, a different vulnerability than CVE-2008-1447.. EPSS estimates a 2.68% chance of exploitation in the next 30 days.
Description
The SERVICE.DNS signature engine in the Intrusion Prevention System (IPS) in Cisco IOS 12.3 and 12.4 allows remote attackers to cause a denial of service (device crash or hang) via network traffic that triggers unspecified IPS signatures, a different vulnerability than CVE-2008-1447.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios | 12.3t |
| Cisco | Ios | 12.3xl |
| Cisco | Ios | 12.3xq |
| Cisco | Ios | 12.3xr |
| Cisco | Ios | 12.3xs |
| Cisco | Ios | 12.3xx |
| Cisco | Ios | 12.3ya |
| Cisco | Ios | 12.3yd |
| Cisco | Ios | 12.3yg |
| Cisco | Ios | 12.3yh |
| Cisco | Ios | 12.3yi |
| Cisco | Ios | 12.3yk |
| Cisco | Ios | 12.3ys |
| Cisco | Ios | 12.3yt |
| Cisco | Ios | 12.3za |
| Cisco | Ios | 12.4xa |
| Cisco | Ios | 12.4xc |
| Cisco | Ios | 12.4xe |
| Cisco | Ios | 12.4xf |
| Cisco | Ios | 12.4xj |
| Cisco | Ios | 12.4xk |
| Cisco | Ios | 12.4xt |
| Cisco | Ios | 12.4xv |
References
- http://secunia.com/advisories/31990Third Party Advisory
- http://www.vupen.com/english/advisories/2008/2670Permissions Required, Third Party Advisory
- http://secunia.com/advisories/31990Third Party Advisory
- http://www.vupen.com/english/advisories/2008/2670Permissions Required, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-2739?
How severe is CVE-2008-2739?
How do I fix CVE-2008-2739?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-2732Multiple unspecified vulnerabilities in the SIP inspection f…
- CVE-2008-2733Cisco PIX and Adaptive Security Appliance (ASA) 5500 devices…
- CVE-2008-2734Memory leak in the crypto functionality in Cisco Adaptive Se…
- CVE-2008-2735The HTTP server in Cisco Adaptive Security Appliance (ASA) 5…
- CVE-2008-2736Unspecified vulnerability in Cisco Adaptive Security Applian…
- CVE-2008-2737Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2008-2742Unrestricted file upload in the mcpuk file editor (atk/attri…
- CVE-2008-2743Cross-site scripting (XSS) vulnerability in the embedded web…
- CVE-2008-2744Cross-site scripting (XSS) vulnerability in vBulletin 3.6.10…
- CVE-2008-2745Stack-based buffer overflow in BiAnno ActiveX Control (BiAnn…
- CVE-2008-2746SQL injection vulnerability in login.php in Gryphon gllcTS2 …
- CVE-2008-2747No-IP Dynamic Update Client (DUC) 2.2.1 on Windows uses weak…
Are you affected by CVE-2008-2739?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
