PT-2002-1035 · Preboot Execution Environment (Pxe) Server+1 · Preboot Execution Environment (Pxe) Server+1
Published
2002-07-29
·
Updated
2008-09-05
·
CVE-2002-0835
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Preboot eXecution Environment (PXE) server (affected versions not specified)
pxe-0.1
Description
The issue allows remote attackers to cause a denial of service, potentially leading to a crash, via certain DHCP packets, such as those from Voice-Over-IP (VOIP) phones. This can result in disruption of protected information availability. The exploitation of this issue can be carried out remotely.
Recommendations
For the Preboot eXecution Environment (PXE) server, consider restricting or filtering DHCP packets from VOIP phones to minimize the risk of denial of service.
For pxe-0.1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Preboot Execution Environment (Pxe) Server
Pxe-0.1