Vulnerability record · CVE-2009-1943 · published 5 June 2009
CVE-2009-1943: SafeNet SoftRemote IKE service stack buffer overflow
Safenet Inc · Softremote
The IKE service (ireIke.exe) in SafeNet SoftRemote before 10.8.6 contains a stack-based buffer overflow reachable through a long request sent to UDP port 62514. A remote, unauthenticated attacker can trigger it and execute arbitrary code on the affected host. The flaw is severe because the service is network-facing and the overflow is pre-authentication.
Description
Stack-based buffer overflow in the IKE service (ireIke.exe) in SafeNet SoftRemote before 10.8.6 allows remote attackers to execute arbitrary code via a long request to UDP port 62514.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityPre-authentication remote code execution in a network-facing service with a CVSS 2.0 base score of 10 and very high EPSS, though no confirmed in-the-wild exploitation is recorded.
What it is
The IKE service (ireIke.exe) in SafeNet SoftRemote before 10.8.6 contains a stack-based buffer overflow reachable through a long request sent to UDP port 62514. A remote, unauthenticated attacker can trigger it and execute arbitrary code on the affected host. The flaw is severe because the service is network-facing and the overflow is pre-authentication.
Impact
An attacker gains remote code execution with the privileges of the IKE service, potentially full control of the endpoint. No confidentiality, integrity or availability impact is excluded by the record.
Attack surface
Reached over the network via a crafted UDP packet to port 62514; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required. The description does not state whether the port is exposed by default or how the service is deployed.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded. EPSS is high (0.7221, 99.4th percentile), and references include a vendor patch advisory but no public exploit tag, so active exploitation is not confirmed by this record.
What to do
- Upgrade SafeNet SoftRemote to 10.8.6 or later per the vendor advisory.
- If the IKE service is not required, disable it; otherwise restrict UDP port 62514 to trusted peers only.
- Segment or firewall hosts running SoftRemote so the IKE port is not reachable from untrusted networks.
- Monitor vendor advisories for updated guidance if the product is still supported.
Detection
- Alert on IKE traffic to UDP port 62514 from unexpected or external sources.
- Watch for ireIke.exe crashes or process restarts that could indicate malformed request handling.
- Hunt for anomalous child processes or network connections spawned by ireIke.exe.
- Review firewall and IDS logs for oversized or malformed UDP payloads targeting port 62514.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-1943 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-1943), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.