CVE-2001-1533

MEDIUM

Microsoft ISA Server 2000 - Denial of Service via UDP Fragment Flood

Title source: llm
STIX 2.1

Description

Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3501
Various Sources mailing-list x_refsource_bugtraq
http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00031.html
Various Sources mailing-list x_refsource_bugtraq
http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00018.html
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/7446.php

Scores

CVSS v3 5.3
EPSS 0.1801
EPSS Percentile 96.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

Status published
Products (1)
microsoft/isa_server 2000
Published Dec 31, 2001
Tracked Since Feb 18, 2026