SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-0551

Cisco CatOS 5.x before 5.5(20) through 8.x before 8.2(2) and 8.3(2)GLX, as used in Catalyst switches, allows remote attackers to cause a denial of service (system crash and reload) by sending invalid packets instead of the final ACK portion of the…

MEDIUM 5.0EPSS 3.13%

Does this matter?

Lower severity and a low EPSS score (3.13%). Track it; it rarely justifies an emergency change on its own.

Description

Cisco CatOS 5.x before 5.5(20) through 8.x before 8.2(2) and 8.3(2)GLX, as used in Catalyst switches, allows remote attackers to cause a denial of service (system crash and reload) by sending invalid packets instead of the final ACK portion of the three-way handshake to the (1) Telnet, (2) HTTP, or (3) SSH services, aka "TCP-ACK DoS attack."

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
3.13% probability · 87th percentile
CISA KEV
Not listed
Affected
cisco/catos · cisco/catalyst 2901 · cisco/catalyst 2902 · cisco/catalyst 2926 · cisco/catalyst 2926f · cisco/catalyst 2926gl · cisco/catalyst 2926gs · cisco/catalyst 2926t · cisco/catalyst 2948 · cisco/catalyst 2948-ge-tx · cisco/catalyst 2948g-l3 · cisco/catalyst 2980g · cisco/catalyst 2980g-a · cisco/catalyst 4000 · cisco/catalyst 4500 · cisco/catalyst 4503 · cisco/catalyst 4506 · cisco/catalyst 4507r · cisco/catalyst 4510r · cisco/catalyst 4912g · +4 more
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.