SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2003-0001

Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.

MEDIUM 5.0EPSS 70.2%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 70.2%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
70.23% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
freebsd/freebsd · linux/linux kernel · microsoft/windows 2000 · microsoft/windows 2000 terminal services · netbsd/netbsd
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.