Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2004-1111


Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and other versions without the "no service dhcp" command, keep undeliverable DHCP packets in the queue instead of dropping them, which allows remote attackers to cause a denial of service (dropped traffic) via multiple undeliverable DHCP packets that exceed the input queue size.


Published

2005-01-10T05:00:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco ios 12.2\(14\)sz Yes
Operating System cisco ios 12.2\(18\)ew Yes
Operating System cisco ios 12.2\(18\)ewa Yes
Operating System cisco ios 12.2\(18\)s Yes
Operating System cisco ios 12.2\(18\)se Yes
Operating System cisco ios 12.2\(18\)sv Yes
Operating System cisco ios 12.2\(18\)sw Yes
Operating System cisco ios 12.2\(20\)ew Yes
Hardware cisco multiservice_platform_2650 * Yes
Hardware cisco multiservice_platform_2650xm * Yes
Hardware cisco multiservice_platform_2651 * Yes
Hardware cisco multiservice_platform_2651xm * Yes
Hardware cisco 7200_router * Yes
Hardware cisco 7300_router * Yes
Hardware cisco 7500_router * Yes
Hardware cisco 7600_router * Yes
Hardware cisco catalyst_7600 * Yes

References