Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2002-0886Cisco Cbos vulnerability

4 documents4 sources
Severity
5.0MEDIUMNVD
EPSS
22.6%
top 4.14%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedOct 4
Latest updateApr 30

Description

Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of service (hang or memory consumption) via (1) a large packet to the DHCP port, (2) a large packet to the Telnet port, or (3) a flood of large packets to the CPE, which causes the TCP/IP stack to consume large amounts of memory.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDcisco/cbos21 versions+20

Patches

🔴Vulnerability Details

2
GHSA
GHSA-32p2-76xv-rj3g: Cisco DSL CPE devices running CBOS 22022-04-30
CVEList
CVE-2002-0886: Cisco DSL CPE devices running CBOS 22002-08-31

💥Exploits & PoCs

1
Exploit-DB
Cisco CBOS 2.x - Broadband Operating System TCP/IP Stack Denial of Service2002-05-23
CVE-2002-0886 — Cisco Cbos vulnerability | cvebase