CVE-2001-1244

UnknownEPSS 35.29%

Last modified

CVE-2001-1244 is a vulnerability of currently unknown severity. Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.. EPSS estimates a 35.29% chance of exploitation in the next 30 days.

Description

Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.

Metrics

EPSS Probability
35.29%

98.2th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
FreebsdFreebsd4.3
HpHp-Ux11.00
HpHp-Ux11.0.4
HpHp-Ux11.11
HpVvos11.04
LinuxLinux Kernel2.4.0
LinuxLinux Kernel2.4.1
LinuxLinux Kernel2.4.2
LinuxLinux Kernel2.4.3
LinuxLinux Kernel2.4.4
LinuxLinux Kernel2.4.5
MicrosoftWindows 2000All versions
MicrosoftWindows Nt4.0
NetbsdNetbsd1.5
NetbsdNetbsd1.5.1
OpenbsdOpenbsd2.8
OpenbsdOpenbsd2.9
SunSunos5.5.1
SunSunos5.7
SunSunos5.8

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2001-1244?
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.
How severe is CVE-2001-1244?
Severity scoring for CVE-2001-1244 is pending analysis. The EPSS model estimates a 35.29% probability of exploitation in the next 30 days.
How do I fix CVE-2001-1244?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2001-1244?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST