CVE-2004-0551
Cisco CatOS 5.x before 5.5(20) through 8.x before 8.2(2) and 8.3(2)GLX, as used in Catalyst switches, allows remote attackers to cause a denial of service (system crash and reload) by sending invalid packets instead of the final ACK portion of the…
Does this matter?
Lower severity and a low EPSS score (3.13%). Track it; it rarely justifies an emergency change on its own.
Description
Cisco CatOS 5.x before 5.5(20) through 8.x before 8.2(2) and 8.3(2)GLX, as used in Catalyst switches, allows remote attackers to cause a denial of service (system crash and reload) by sending invalid packets instead of the final ACK portion of the three-way handshake to the (1) Telnet, (2) HTTP, or (3) SSH services, aka "TCP-ACK DoS attack."
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 3.13% probability · 87th percentile
- CISA KEV
- Not listed
- Affected
- cisco/catos · cisco/catalyst 2901 · cisco/catalyst 2902 · cisco/catalyst 2926 · cisco/catalyst 2926f · cisco/catalyst 2926gl · cisco/catalyst 2926gs · cisco/catalyst 2926t · cisco/catalyst 2948 · cisco/catalyst 2948-ge-tx · cisco/catalyst 2948g-l3 · cisco/catalyst 2980g · cisco/catalyst 2980g-a · cisco/catalyst 4000 · cisco/catalyst 4500 · cisco/catalyst 4503 · cisco/catalyst 4506 · cisco/catalyst 4507r · cisco/catalyst 4510r · cisco/catalyst 4912g · +4 more
- Source
- cve@mitre.org
References
- http://www.cisco.com/warp/public/707/cisco-sa-20040609-catos.shtml
- http://www.kb.cert.org/vuls/id/245190Third Party Advisory, US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16370
- http://www.cisco.com/warp/public/707/cisco-sa-20040609-catos.shtml
- http://www.kb.cert.org/vuls/id/245190Third Party Advisory, US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16370
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.