HIGH · 7.1

CVE-2002-1024

Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection ...

Vulnerability Description

Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144).

CVSS Score

7.1

HIGH

AV:N/AC:M/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoIos12.0s
CiscoPix Firewall Software5.2
CiscoCss11000 Content Services SwitchAll versions
CiscoCatos5.3\(1\)csx

Related Weaknesses (CWE)

References

FAQ

What is CVE-2002-1024?

CVE-2002-1024 is a vulnerability with a CVSS score of 7.1 (HIGH). Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection ...

How severe is CVE-2002-1024?

CVE-2002-1024 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-1024?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios, Cisco Pix Firewall Software, Cisco Css11000 Content Services Switch, Cisco Catos.