CVE-2007-4654
Unspecified vulnerability in SSHield 1.6.1 with OpenSSH 3.0.2p1 on Cisco WebNS 8.20.0.1 on Cisco Content Services Switch (CSS) series 11000 devices allows remote attackers to cause a denial of service (connection slot exhaustion and device crash) via a…
Does this matter?
Lower severity and a low EPSS score (1.96%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in SSHield 1.6.1 with OpenSSH 3.0.2p1 on Cisco WebNS 8.20.0.1 on Cisco Content Services Switch (CSS) series 11000 devices allows remote attackers to cause a denial of service (connection slot exhaustion and device crash) via a series of large packets designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144), possibly a related issue to CVE-2002-1024.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 1.96% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- cisco/webns · openbsd/openssh · teamf1/sshield
- Source
- cve@mitre.org
References
- http://osvdb.org/45873
- http://securityreason.com/securityalert/3091
- http://www.securityfocus.com/archive/1/478165/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44542
- http://osvdb.org/45873
- http://securityreason.com/securityalert/3091
- http://www.securityfocus.com/archive/1/478165/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44542
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.