CVE-2001-1533
MEDIUMMicrosoft ISA Server 2000 - Denial of Service via UDP Fragment Flood
Title source: llmDescription
Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/3501
Various Sources mailing-list
x_refsource_bugtraq
http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00031.html
Various Sources mailing-list
x_refsource_bugtraq
http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00018.html
Third Party Advisory vdb-entry
x_refsource_xf
http://www.iss.net/security_center/static/7446.php
Scores
CVSS v3
5.3
EPSS
0.1801
EPSS Percentile
96.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
Status
published
Products (1)
microsoft/isa_server
2000
Published
Dec 31, 2001
Tracked Since
Feb 18, 2026