CVE-2004-0551
Last modified
CVE-2004-0551 is a vulnerability of currently unknown severity. Cisco CatOS 5.x before 5.5(20) through 8.x before 8.2(2) and 8.3(2)GLX, as used in Catalyst switches, allows remote attackers to cause a denial of service (system crash and reload) by sending invalid packets instead of the final ACK portion of the three-way handshake to the (1) Telnet, (2) HTTP, or (3) SSH services, aka "TCP-ACK DoS attack.". EPSS estimates a 3.13% chance of exploitation in the next 30 days.
Description
Cisco CatOS 5.x before 5.5(20) through 8.x before 8.2(2) and 8.3(2)GLX, as used in Catalyst switches, allows remote attackers to cause a denial of service (system crash and reload) by sending invalid packets instead of the final ACK portion of the three-way handshake to the (1) Telnet, (2) HTTP, or (3) SSH services, aka "TCP-ACK DoS attack."
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Catos | 2.1\(1\) |
| Cisco | Catos | 2.1\(2\) |
| Cisco | Catos | 2.1\(3\) |
| Cisco | Catos | 2.1\(4\) |
| Cisco | Catos | 2.1\(5\) |
| Cisco | Catos | 2.1\(6\) |
| Cisco | Catos | 2.1\(7\) |
| Cisco | Catos | 2.1\(8\) |
| Cisco | Catos | 2.1\(9\) |
| Cisco | Catos | 2.1\(10\) |
| Cisco | Catos | 2.1\(11\) |
| Cisco | Catos | 2.1\(12\) |
| Cisco | Catos | 2.2\(1\) |
| Cisco | Catos | 2.2\(2\) |
| Cisco | Catos | 2.3\(1\) |
| Cisco | Catos | 2.4\(1\) |
| Cisco | Catos | 2.4\(2\) |
| Cisco | Catos | 2.4\(3\) |
| Cisco | Catos | 2.4\(4\) |
| Cisco | Catos | 2.4\(5\) |
| Cisco | Catos | 2.4\(5a\) |
| Cisco | Catos | 3.0\(7\) |
| Cisco | Catos | 3.1\(1\) |
| Cisco | Catos | 3.1\(2\) |
| Cisco | Catos | 3.1\(2a\) |
| Cisco | Catos | 3.2\(1\) |
| Cisco | Catos | 3.2\(1b\) |
| Cisco | Catos | 3.2\(2\) |
| Cisco | Catos | 3.2\(3\) |
| Cisco | Catos | 3.2\(4\) |
| Cisco | Catos | 3.2\(5\) |
| Cisco | Catos | 3.2\(6\) |
| Cisco | Catos | 3.2\(7\) |
| Cisco | Catos | 3.2\(8\)gdr |
| Cisco | Catos | 4.1\(1\) |
| Cisco | Catos | 4.1\(2\) |
| Cisco | Catos | 4.1\(3\) |
| Cisco | Catos | 4.2\(1\) |
| Cisco | Catos | 4.2\(2\) |
| Cisco | Catos | 4.3\(1a\) |
| Cisco | Catos | 4.4\(1\) |
| Cisco | Catos | 4.5\(1\) |
| Cisco | Catos | 4.5\(2\) |
| Cisco | Catos | 4.5\(3\) |
| Cisco | Catos | 4.5\(4\) |
| Cisco | Catos | 4.5\(5\) |
| Cisco | Catos | 4.5\(6\) |
| Cisco | Catos | 4.5\(6a\) |
| Cisco | Catos | 4.5\(7\) |
| Cisco | Catos | 4.5\(8\) |
Showing 50 of 238 affected configurations. See NVD for the full list.
References
- http://www.kb.cert.org/vuls/id/245190Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/245190Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-0551?
How severe is CVE-2004-0551?
How do I fix CVE-2004-0551?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-0544Multiple buffer overflows in LVM for AIX 5.1 and 5.2 allow l…
- CVE-2004-0545LVM for AIX 5.1 and 5.2 allows local users to overwrite arbi…
- CVE-2004-0547Buffer overflow in the ODBC driver for PostgreSQL before 7.2…
- CVE-2004-0548Multiple stack-based buffer overflows in the word-list-compr…
- CVE-2004-0549The WebBrowser ActiveX control, or the Internet Explorer HTM…
- CVE-2004-0550Buffer overflow in Real Networks RealPlayer 10 allows remote…
- CVE-2004-0552Sophos Small Business Suite 1.00 on Windows does not properl…
- CVE-2004-0554Linux kernel 2.4.x and 2.6.x for x86 allows local users to c…
- CVE-2004-0555Buffer overflow in (1) queue.c and (2) queued.c in queue bef…
- CVE-2004-0556Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2004-0557Multiple buffer overflows in the st_wavstartread function in…
- CVE-2004-0558The Internet Printing Protocol (IPP) implementation in CUPS …
Are you affected by CVE-2004-0551?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
