CVE-2002-2208
Last modified
CVE-2002-2208 is a vulnerability of currently unknown severity. Extended Interior Gateway Routing Protocol (EIGRP), as implemented in Cisco IOS 11.3 through 12.2 and other products, allows remote attackers to cause a denial of service (flood) by sending a large number of spoofed EIGRP neighbor announcements, which results in an ARP storm on the local network.. EPSS estimates a 4.27% chance of exploitation in the next 30 days.
Description
Extended Interior Gateway Routing Protocol (EIGRP), as implemented in Cisco IOS 11.3 through 12.2 and other products, allows remote attackers to cause a denial of service (flood) by sending a large number of spoofed EIGRP neighbor announcements, which results in an ARP storm on the local network.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Extended Interior Gateway Routing Protocol | Extended Interior Gateway Routing Protocol | 1.2 |
| Cisco | Ios | 11.3 |
| Cisco | Ios | 12.0 |
| Cisco | Ios | 12.1 |
| Cisco | Ios | 12.2 |
References
- http://secunia.com/advisories/7766Vendor Advisory
- http://www.cisco.com/warp/public/707/eigrp_issue.pdfVendor Advisory
- http://www.securityfocus.com/archive/1/304034Vendor Advisory
- http://secunia.com/advisories/7766Vendor Advisory
- http://www.cisco.com/warp/public/707/eigrp_issue.pdfVendor Advisory
- http://www.securityfocus.com/archive/1/304034Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-2208?
How severe is CVE-2002-2208?
How do I fix CVE-2002-2208?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2002
- CVE-2002-2202Outlook Express 6.0 does not delete messages from dbx files,…
- CVE-2002-2203Unknown vulnerability in the System Serial Console terminal …
- CVE-2002-2204The default --checksig setting in RPM Package Manager 4.0.4 …
- CVE-2002-2205Buffer overflow in Webresolve 0.1.0 and earlier allows remot…
- CVE-2002-2206The POP3 proxy service (POPROXY.EXE) in Norton AntiVirus 200…
- CVE-2002-2207Buffer overflow in ssldump 0.9b2 and earlier, when running i…
- CVE-2002-2209Unspecified "security vulnerability" in Baby FTP Server vers…
- CVE-2002-2210The installation of OpenOffice 1.0.1 allows local users to o…
- CVE-2002-2211BIND 4 and BIND 8, when resolving recursive DNS queries for …
- CVE-2002-2212The DNS resolver in unspecified versions of Fujitsu UXP/V, w…
- CVE-2002-2213The DNS resolver in unspecified versions of Infoblox DNS One…
- CVE-2002-2214The php_if_imap_mime_header_decode function in the IMAP func…
Are you affected by CVE-2002-2208?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
