CVE-2001-0877
Last modified
CVE-2001-0877 is a vulnerability of currently unknown severity. Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service via (1) a spoofed SSDP advertisement that causes the client to connect to a service on another machine that generates a large amount of traffic (e.g., chargen), or (2) via a spoofed SSDP announcement to broadcast or multicast addresses, which could cause all UPnP clients to send traffic to a single target system.. EPSS estimates a 37.18% chance of exploitation in the next 30 days.
Description
Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service via (1) a spoofed SSDP advertisement that causes the client to connect to a service on another machine that generates a large amount of traffic (e.g., chargen), or (2) via a spoofed SSDP announcement to broadcast or multicast addresses, which could cause all UPnP clients to send traffic to a single target system.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Windows 98 | All versions | Gold |
| Microsoft | Windows 98se | All versions | — |
| Microsoft | Windows Me | All versions | — |
| Microsoft | Windows Xp | All versions | Gold |
References
- http://www.cert.org/advisories/CA-2001-37.htmlPatch, Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/411059US Government Resource
- http://www.securityfocus.com/archive/1/249238Vendor Advisory
- http://www.cert.org/advisories/CA-2001-37.htmlPatch, Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/411059US Government Resource
- http://www.securityfocus.com/archive/1/249238Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-0877?
How severe is CVE-2001-0877?
How do I fix CVE-2001-0877?
Are you affected by CVE-2001-0877?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
