PT-2002-1035 · Preboot Execution Environment (Pxe) Server+1 · Preboot Execution Environment (Pxe) Server+1

Published

2002-07-29

·

Updated

2008-09-05

·

CVE-2002-0835

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Preboot eXecution Environment (PXE) server (affected versions not specified) pxe-0.1
Description The issue allows remote attackers to cause a denial of service, potentially leading to a crash, via certain DHCP packets, such as those from Voice-Over-IP (VOIP) phones. This can result in disruption of protected information availability. The exploitation of this issue can be carried out remotely.
Recommendations For the Preboot eXecution Environment (PXE) server, consider restricting or filtering DHCP packets from VOIP phones to minimize the risk of denial of service. For pxe-0.1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07869
CVE-2002-0835

Affected Products

Preboot Execution Environment (Pxe) Server
Pxe-0.1