Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2002-0886


Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of service (hang or memory consumption) via (1) a large packet to the DHCP port, (2) a large packet to the Telnet port, or (3) a flood of large packets to the CPE, which causes the TCP/IP stack to consume large amounts of memory.


Published

2002-10-04T04:00:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco cbos 2.0.1 Yes
Operating System cisco cbos 2.1.0 Yes
Operating System cisco cbos 2.1.0a Yes
Operating System cisco cbos 2.2.0 Yes
Operating System cisco cbos 2.2.1 Yes
Operating System cisco cbos 2.2.1a Yes
Operating System cisco cbos 2.3 Yes
Operating System cisco cbos 2.3.2 Yes
Operating System cisco cbos 2.3.5 Yes
Operating System cisco cbos 2.3.5.015 Yes
Operating System cisco cbos 2.3.7 Yes
Operating System cisco cbos 2.3.7.002 Yes
Operating System cisco cbos 2.3.8 Yes
Operating System cisco cbos 2.3.9 Yes
Operating System cisco cbos 2.3_.053 Yes
Operating System cisco cbos 2.4.1 Yes
Operating System cisco cbos 2.4.2 Yes
Operating System cisco cbos 2.4.2ap Yes
Operating System cisco cbos 2.4.2b Yes
Operating System cisco cbos 2.4.3 Yes
Operating System cisco cbos 2.4.4 Yes

References