« Volver al listado

CVE-2009-4118

Estado: ModificadaBaja (2.1)—

The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0100 does not properly handle an ERROR_FAILED_SERVICE_CONTROLLER_CONNECT error, which allows local users to cause a denial of service (service crash and VPN connection loss) via a manual start of cvpnd.exe while the cvpnd service is running.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-4118",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-12-01T00:30:00.233",
  "references": [
    {
      "url": "http://packetstormsecurity.org/0911-exploits/sybsec-adv17.txt",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/37419",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://tools.cisco.com/security/center/viewAlert.x?alertId=19445",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/37077",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/3296",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://packetstormsecurity.org/0911-exploits/sybsec-adv17.txt",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/37419",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://tools.cisco.com/security/center/viewAlert.x?alertId=19445",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/37077",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/3296",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0100 does not properly handle an ERROR_FAILED_SERVICE_CONTROLLER_CONNECT error, which allows local users to cause a denial of service (service crash and VPN connection loss) via a manual start of cvpnd.exe while the cvpnd service is running."
    },
    {
      "lang": "es",
      "value": "La función StartServiceCtrlDispatcher en el servicio cvpnd (cvpnd.exe) del cliente Cisco VPN para Windows versiones anteriores a 5.0.06.0100 no maneja correctamente un error ERROR_FAILED_SERVICE_CONTROLLER_CONNECT, permitiendo que usuarios locales provoquen una denegación de servicio (parada del servicio y perdida de conexión VPN) mediante un inicio manual de cvpnd.exe mientras se está ejecutando el servicio cvpnd."
    }
  ],
  "lastModified": "2026-06-16T23:13:04.523",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cisco:vpn_client:2.0:*:windows:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "398B68C7-C1DB-4A62-B0A2-89C917768E58"
            },
            {
              "criteria": "cpe:2.3:a:cisco:vpn_client:3.0:*:windows:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20C66C87-1367-4440-A2C2-E6B657DA2743"
            },
            {
              "criteria": "cpe:2.3:a:cisco:vpn_client:3.0.5:*:windows:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D4BFB291-672C-437E-BBF4-B00D89C11EA9"
            },
            {
              "criteria": "cpe:2.3:a:cisco:vpn_client:3.1:*:windows:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A270D7C-ACBC-41A4-A606-8A4F35894E74"
            },
            {
              "criteria": "cpe:2.3:a:cisco:vpn_client:3.5.1:*:windows:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "59938F7D-5F64-4FC0-A5B2-C798AF297130"
            },
            {
              "criteria": "cpe:2.3:a:cisco:vpn_client:3.5.1c:*:windows:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76060A99-ED0C-4125-B67E-FA8E4F57AAB5"
            },
            {
              "criteria": "cpe:2.3:a:cisco:vpn_client:3.5.2:*:windows:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2288FB91-4607-417D-8658-E1B8090BE40A"
            },
            {
              "criteria": "cpe:2.3:a:cisco:vpn_client:3.6.5:base:windows:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1DED262D-1757-4E0A-8AB4-E76CF2E30131"
            },
            {
              "criteria": "cpe:2.3:a:cisco:vpn_client:4.7.00.0000:*:windows:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2039E7C3-E623-4ADC-B851-55BC33FA760D"
            },
            {
              "criteria": "cpe:2.3:a:cisco:vpn_client:4.8.00.0000:*:windows:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C3777CC-C18F-4F93-8DD4-A0A348EDA1D6"
            },
            {
              "criteria": "cpe:2.3:a:cisco:vpn_client:4.8.00.0440:*:windows:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CD4F8C6B-6134-4049-AA55-F229ABEC59EB"
            },
            {
              "criteria": "cpe:2.3:a:cisco:vpn_client:4.8.1:*:windows:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8FD6C3C5-A7D3-4208-A23C-BA7D5626FB92"
            },
            {
              "criteria": "cpe:2.3:a:cisco:vpn_client:4.8.01:base:windows:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5BAD012F-35CA-4C78-9825-C7C12B99DC17"
            },
            {
              "criteria": "cpe:2.3:a:cisco:vpn_client:4.8.02.0010:base:windows:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E793DFC-403A-4077-92C0-9D2F8FB01F0B"
            },
            {
              "criteria": "cpe:2.3:a:cisco:vpn_client:4.9:base:windows:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "69C15D7C-024E-460B-A7D4-B2D28A77EB2A"
            },
            {
              "criteria": "cpe:2.3:a:cisco:vpn_client:5.0.00.340:base:windows:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "422898BF-B544-4A36-8A05-1A8FFF63EE2A"
            },
            {
              "criteria": "cpe:2.3:a:cisco:vpn_client:5.0.01:*:windows:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C7255DB0-EB00-44E5-A9DC-D0908090E99E"
            },
            {
              "criteria": "cpe:2.3:a:cisco:vpn_client:5.0.01.0600:base:windows:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8263AEA7-D507-4036-AF23-B451B92F5726"
            },
            {
              "criteria": "cpe:2.3:a:cisco:vpn_client:5.0.2.0090:*:windows:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DF3345B2-964B-49CF-9531-69B129A57AF3"
            },
            {
              "criteria": "cpe:2.3:a:cisco:vpn_client:5.0.02.0090:base:windows:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02241496-C9CD-486C-B675-830B6E28A860"
            },
            {
              "criteria": "cpe:2.3:a:cisco:vpn_client:0490:base:windows:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA0BC63F-B1FF-4ED3-A02E-6DED9CEBC14F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}