PT-2001-2618 · Microsoft · Internet Security/Acceleration (Isa) Server 2000

Published

2001-12-31

·

Updated

2025-01-16

·

CVE-2001-1533

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Microsoft Internet Security and Acceleration (ISA) Server 2000
Description The issue allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. The vendor disputes this issue, stating that it requires high bandwidth to exploit and does not cause server instability.
Recommendations For Microsoft Internet Security and Acceleration (ISA) Server 2000, consider implementing rate limiting or traffic filtering to minimize the risk of exploitation from fragmented UDP packets. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2001-1533

Affected Products

Internet Security/Acceleration (Isa) Server 2000