CVE-2004-1112
Last modified
CVE-2004-1112 is a vulnerability of currently unknown severity. The buffer overflow trigger in Cisco Security Agent (CSA) before 4.0.3 build 728 waits five minutes for a user response before terminating the process, which could allow remote attackers to bypass the buffer overflow protection by sending additional buffer overflow attacks within the five minute timeout period.. EPSS estimates a 1.50% chance of exploitation in the next 30 days.
Description
The buffer overflow trigger in Cisco Security Agent (CSA) before 4.0.3 build 728 waits five minutes for a user response before terminating the process, which could allow remote attackers to bypass the buffer overflow protection by sending additional buffer overflow attacks within the five minute timeout period.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Security Agent | 3 |
| Cisco | Security Agent | 4.0 |
| Cisco | Security Agent | 4.0.1 |
| Cisco | Security Agent | 4.0.2 |
| Cisco | Security Agent | 4.0.3 |
| Okena | Stormwatch | 3.x |
References
- http://www.ciac.org/ciac/bulletins/p-036.shtmlVendor Advisory
- http://www.securityfocus.com/bid/11659Vendor Advisory
- http://www.ciac.org/ciac/bulletins/p-036.shtmlVendor Advisory
- http://www.securityfocus.com/bid/11659Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-1112?
How severe is CVE-2004-1112?
How do I fix CVE-2004-1112?
Are you affected by CVE-2004-1112?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
