MEDIUM · 5.0

CVE-2004-1111

Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and other versions without the "no service dhcp" command, keep undeliverable DHCP packets in the queue inst...

Vulnerability Description

Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and other versions without the "no service dhcp" command, keep undeliverable DHCP packets in the queue instead of dropping them, which allows remote attackers to cause a denial of service (dropped traffic) via multiple undeliverable DHCP packets that exceed the input queue size.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
CiscoIos12.2\(14\)sz
CiscoMultiservice Platform 2650All versions
CiscoMultiservice Platform 2650XmAll versions
CiscoMultiservice Platform 2651All versions
CiscoMultiservice Platform 2651XmAll versions
Cisco7200 RouterAll versions
Cisco7300 RouterAll versions
Cisco7500 RouterAll versions
Cisco7600 RouterAll versions
CiscoCatalyst 7600All versions

References

FAQ

What is CVE-2004-1111?

CVE-2004-1111 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and other versions without the "no service dhcp" command, keep undeliverable DHCP packets in the queue inst...

How severe is CVE-2004-1111?

CVE-2004-1111 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-1111?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios, Cisco Multiservice Platform 2650, Cisco Multiservice Platform 2650Xm, Cisco Multiservice Platform 2651, Cisco Multiservice Platform 2651Xm.