CVE-2004-1111
Last modified
CVE-2004-1111 is a vulnerability of currently unknown severity. Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and other versions without the "no service dhcp" command, keep undeliverable DHCP packets in the queue instead of dropping them, which allows remote attackers to cause a denial of service (dropped traffic) via multiple undeliverable DHCP packets that exceed the input queue size.. EPSS estimates a 2.34% chance of exploitation in the next 30 days.
Description
Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and other versions without the "no service dhcp" command, keep undeliverable DHCP packets in the queue instead of dropping them, which allows remote attackers to cause a denial of service (dropped traffic) via multiple undeliverable DHCP packets that exceed the input queue size.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios | 12.2\(14\)sz |
| Cisco | Ios | 12.2\(18\)ew |
| Cisco | Ios | 12.2\(18\)ewa |
| Cisco | Ios | 12.2\(18\)s |
| Cisco | Ios | 12.2\(18\)se |
| Cisco | Ios | 12.2\(18\)sv |
| Cisco | Ios | 12.2\(18\)sw |
| Cisco | Ios | 12.2\(20\)ew |
| Cisco | Multiservice Platform 2650 | All versions |
| Cisco | Multiservice Platform 2650xm | All versions |
| Cisco | Multiservice Platform 2651 | All versions |
| Cisco | Multiservice Platform 2651xm | All versions |
| Cisco | 7200 Router | All versions |
| Cisco | 7300 Router | All versions |
| Cisco | 7500 Router | All versions |
| Cisco | 7600 Router | All versions |
| Cisco | Catalyst 7600 | All versions |
References
- http://www.kb.cert.org/vuls/id/630104Third Party Advisory, US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA04-316A.htmlUS Government Resource
- http://www.kb.cert.org/vuls/id/630104Third Party Advisory, US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA04-316A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-1111?
How severe is CVE-2004-1111?
How do I fix CVE-2004-1111?
Are you affected by CVE-2004-1111?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
