PT-2002-1897 · Cisco · Cisco Dsl Cpe

Published

2002-08-31

·

Updated

2017-07-11

·

CVE-2002-0886

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Cisco DSL CPE devices version 2.4.4 and earlier
Description: The issue allows remote attackers to cause a denial of service, resulting in the device hanging or consuming large amounts of memory. This can be achieved by sending a large packet to the DHCP port, the Telnet port, or by flooding the CPE with large packets, which causes the TCP/IP stack to consume large amounts of memory.
Recommendations: For versions 2.4.4 and earlier, consider restricting access to the DHCP and Telnet ports to minimize the risk of exploitation. As a temporary workaround, implement rate limiting to prevent floods of large packets to the CPE.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0886

Affected Products

Cisco Dsl Cpe