CVE-2002-1024

CWE-3995 documents4 sources
Severity
7.1HIGH
EPSS
4.9%
top 10.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 4
Latest updateApr 30

Description

Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144).

CVSS vector

AV:N/AC:M/C:N/I:N/A:CExploitability: 8.6 | Impact: 6.9

Affected Packages3 packages

NVDcisco/ios64 versions+63
NVDcisco/catos32 versions+31
NVDcisco/pix_firewall_software5 versions+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-98x9-358f-pg9v: Cisco IOS 122022-04-30
CVEList
CVE-2002-1024: Cisco IOS 122003-04-02

💥Exploits & PoCs

2
Exploit-DB
PlanetWeb 1.14 - GET Buffer Overflow2002-09-16
Exploit-DB
psyBNC 2.3 - Denial of Service2002-05-19
CVE-2002-1024 (HIGH CVSS 7.1) | Cisco IOS 12.0 through 12.2 | cvebase.io