CVE-2004-1112

3 documents3 sources
Severity
5.1MEDIUM
EPSS
0.9%
top 24.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateApr 29

Description

The buffer overflow trigger in Cisco Security Agent (CSA) before 4.0.3 build 728 waits five minutes for a user response before terminating the process, which could allow remote attackers to bypass the buffer overflow protection by sending additional buffer overflow attacks within the five minute timeout period.

CVSS vector

AV:N/AC:H/C:P/I:P/A:PExploitability: 4.9 | Impact: 6.4

Affected Packages2 packages

NVDcisco/security_agent5 versions+4

🔴Vulnerability Details

2
GHSA
GHSA-p44m-phj9-qm2q: The buffer overflow trigger in Cisco Security Agent (CSA) before 42022-04-29
CVEList
CVE-2004-1112: The buffer overflow trigger in Cisco Security Agent (CSA) before 42004-12-01
CVE-2004-1112 (MEDIUM CVSS 5.1) | The buffer overflow trigger in Cisc | cvebase.io