Vulnerability CVE-2004-0551


Published: 2004-08-06   Modified: 2012-02-12

Description:
Cisco CatOS 5.x before 5.5(20) through 8.x before 8.2(2) and 8.3(2)GLX, as used in Catalyst switches, allows remote attackers to cause a denial of service (system crash and reload) by sending invalid packets instead of the final ACK portion of the three-way handshake to the (1) Telnet, (2) HTTP, or (3) SSH services, aka "TCP-ACK DoS attack."

Vendor: Cisco
Product: Catos 
Version:
8.3glx
8.3(1)glx
8.2(1)
8.2
8.1(3)
8.1(2)
8.1
7.6(5)
7.6(4)
7.6(3)
7.6(2)
7.6(1)
7.6
7.5(1)
7.5
7.4(3)
7.4(2)
7.4(1)
7.4(0.63)
7.4(0.2)clr
7.4
7.3(2)
7.3(1)
7.3
7.2(2)
7.2(1)
7.2(0.65)
7.1(2a)
7.1(2)
7.1(1a)
7.1(1)
7.1
6.4(8)
6.4(7)
6.4(6)
6.4(5)
6.4(4a)
6.4(3)
6.4(2)
6.4(1)
6.3(9)
6.3(8.3)
6.3(8)
6.3(7)
6.3(6)
6.3(5.10)
6.3(5)
6.3(4a)
6.3(4)
6.3(3a)
6.3(3)x1
6.3(3)x
6.3(3)
6.3(2a)
6.3(2)
6.3(1a)
6.3(10)
6.3(1)
6.3(0.7)pan
6.2(3a)
6.2(3)
6.2(2a)
6.2(2)
6.2(1a)
6.2(1)
6.2(0.111)
6.2(0.110)
6.1(4b)
6.1(4)
6.1(3a)
6.1(3)
6.1(2a)
6.1(2.13)
6.1(2)
6.1(1e)
6.1(1d)
6.1(1c)
6.1(1b)
6.1(1a)
6.1(1)
6.1
5.5(9)
5.5(8a)cv
5.5(8a)
5.5(8)
5.5(7a)
5.5(7)
5.5(6a)
5.5(6)
5.5(5)
5.5(4b)
5.5(4a)
5.5(4)
5.5(3)
5.5(2)
5.5(1a)
5.5(19)
5.5(18)
5.5(17)
5.5(16.2)
See more versions on NVD

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial

 References:
http://www.kb.cert.org/vuls/id/245190
http://xforce.iss.net/xforce/xfdb/16370
http://www.cisco.com/warp/public/707/cisco-sa-20040609-catos.shtml

Related CVE
CVE-2019-1840
A vulnerability in the DHCPv6 input packet processor of Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to restart the server and cause a denial of service (DoS) condition on the affected system. The vulnerability is due...
CVE-2019-1837
A vulnerability in the User Data Services (UDS) API of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the management GUI. The vulnerability is due to i...
CVE-2019-1835
A vulnerability in the CLI of Cisco Aironet Access Points (APs) could allow an authenticated, local attacker to access sensitive information stored in an AP. The vulnerability is due to improper sanitization of user-supplied input in specific CLI com...
CVE-2019-1834
A vulnerability in the internal packet processing of Cisco Aironet Series Access Points (APs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected AP if the switch interface where the AP is con...
CVE-2019-1831
A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper ...
CVE-2019-1830
A vulnerability in Locally Significant Certificate (LSC) management for the Cisco Wireless LAN Controller (WLC) could allow an authenticated, remote attacker to cause the device to unexpectedly restart, which causes a denial of service (DoS) conditio...
CVE-2019-1805
A vulnerability in certain access control mechanisms for the Secure Shell (SSH) server implementation for Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to access a CLI instance on an affected device. T...
CVE-2019-1802
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an a...

Copyright 2019, cxsecurity.com

 

Back to Top