CVE-2009-5039 describes a memory leak vulnerability in the H.323 implementation of Cisco IOS, specifically within the gk_circuit_info_do_in_acf function. This flaw allows remote attackers to trigger a denial of service by causing memory exhaustion through a sustained high volume of calls, such as InterZone Clear Token (IZCT) test traffic. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P), it is a medium severity issue that can be exploited remotely with low complexity and no authentication, leading to partial availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.0\(1\)xaCPE matchmatch criteria | cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.