CVE-2002-1024

Cisco IOS 12.0-12.2 - Denial of Service via Large SSH Packet

Title source: llm
STIX 2.1

Description

Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144).

References (4)

Core 4
Core References
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5114
Patch, Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9437.php
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/290140
Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/warp/public/707/SSH-scanning.shtml

Scores

EPSS 0.0330
EPSS Percentile 87.2%

Details

CWE
CWE-399
Status published
Products (50)
cisco/catos 5.3\(1\)csx
cisco/catos 5.3\(1a\)csx
cisco/catos 5.3\(2\)csx
cisco/catos 5.3\(3\)csx
cisco/catos 5.3\(4\)csx
cisco/catos 5.3\(5\)csx
cisco/catos 5.3\(5a\)csx
cisco/catos 5.3\(6\)csx
cisco/catos 5.4
cisco/catos 5.4\(1\)
... and 40 more
Published Oct 04, 2002
Tracked Since Feb 18, 2026