Vulnerability Description
Multiple Cisco networking products allow remote attackers to cause a denial of service on the local network via a series of ARP packets sent to the router's interface that contains a different MAC address for the router, which eventually causes the router to overwrite the MAC address in its ARP table.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Catalyst 2900Xl | All versions |
| Cisco | Catalyst 2948G-L3 | All versions |
| Cisco | Catalyst 2950 | All versions |
| Cisco | Catalyst 3500Xl | All versions |
| Cisco | Catalyst 3550 | All versions |
| Cisco | Catalyst 4000 | All versions |
| Cisco | Catalyst 4908G-L3 | All versions |
| Cisco | Catalyst 5000 | All versions |
| Cisco | Catalyst 6000 | All versions |
| Cisco | Catalyst 8500 | All versions |
| Cisco | Distributed Director | All versions |
References
- http://www.cisco.com/warp/public/707/IOS-arp-overwrite-vuln-pub.shtmlPatchVendor Advisory
- http://www.kb.cert.org/vuls/id/399355US Government Resource
- http://www.osvdb.org/807
- http://www.securityfocus.com/bid/3547
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7547
- http://www.cisco.com/warp/public/707/IOS-arp-overwrite-vuln-pub.shtmlPatchVendor Advisory
- http://www.kb.cert.org/vuls/id/399355US Government Resource
- http://www.osvdb.org/807
- http://www.securityfocus.com/bid/3547
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7547
FAQ
What is CVE-2001-0895?
CVE-2001-0895 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Multiple Cisco networking products allow remote attackers to cause a denial of service on the local network via a series of ARP packets sent to the router's interface that contains a different MAC add...
How severe is CVE-2001-0895?
CVE-2001-0895 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-0895?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Catalyst 2900Xl, Cisco Catalyst 2948G-L3, Cisco Catalyst 2950, Cisco Catalyst 3500Xl, Cisco Catalyst 3550.