PT-2002-1897 · Cisco · Cisco Dsl Cpe
Published
2002-08-31
·
Updated
2017-07-11
·
CVE-2002-0886
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
Cisco DSL CPE devices version 2.4.4 and earlier
Description:
The issue allows remote attackers to cause a denial of service, resulting in the device hanging or consuming large amounts of memory. This can be achieved by sending a large packet to the
DHCP port, the Telnet port, or by flooding the CPE with large packets, which causes the TCP/IP stack to consume large amounts of memory.Recommendations:
For versions 2.4.4 and earlier, consider restricting access to the DHCP and Telnet ports to minimize the risk of exploitation. As a temporary workaround, implement rate limiting to prevent floods of large packets to the CPE.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Dsl Cpe