Metrics
Metrics |
Score |
Severity |
CVSS Vector |
Source |
V2 |
5 |
|
AV:N/AC:L/Au:N/C:N/I:N/A:P |
[email protected] |
EPSS
EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.
EPSS Score
The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.
EPSS Percentile
The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.
Exploit information
Exploit Database EDB-ID : 20323
Publication date : 2000-10-24 22h00 +00:00
Author : Alberto Solino
EDB Verified : Yes
source: https://www.securityfocus.com/bid/1838/info
Cisco devices running IOS software may be prone to a denial of service attack if a URL containing a question mark followed by a slash (?/) is requested. The device will enter an infinite loop when supplied with a URL containing a "?/" and an enable password. Subsequently, the router will crash in two minutes after the watchdog timer has expired and will then reload. In certain cases, the device will not reload and a restart would be required in order to regain normal functionality.
This vulnerability is restricted to devices that do not have the enable password set or if the password is known or can be easily predicted. The vulnerable service is only on by default in the Cisco 1003, 1004 and 1005 routers.
Users can identify vulnerable or invulnerable devices running IOS by logging onto the device and issuing the ?show version? command. If IOS is running on a vulnerable device the command will return ?Internetwork Operating System Software? or ?IOS (tm)? with a version number.
Vulnerable IOS software may be found on the following Cisco devices:
*Cisco routers in the AGS/MGS/CGS/AGS+, IGS, RSM, 800, ubr900, 1000, 1400, 1500, 1600, 1700, 2500, 2600, 3000, 3600, 3800, 4000, 4500, 4700, AS5200, AS5300, AS5800, 6400, 7000, 7200, ubr7200, 7500, and 12000 series.
*Recent versions of LS1010 ATM switch.
*Catalyst 6000 with IOS.
*Catalyst 2900XL LAN switch with IOS.
*Cisco DistributedDirector.
http://target/anytext?/
Products Mentioned
Configuraton 0
Cisco>>Ios >> Version 12.0t
Cisco>>Ios >> Version 12.0w5
Cisco>>Ios >> Version 12.0xa
Cisco>>Ios >> Version 12.0xe
Cisco>>Ios >> Version 12.0xh
Cisco>>Ios >> Version 12.0xj
Cisco>>Ios >> Version 12.1aa
Cisco>>Ios >> Version 12.1da
Cisco>>Ios >> Version 12.1db
Cisco>>Ios >> Version 12.1dc
Cisco>>Ios >> Version 12.1ec
Cisco>>Ios >> Version 12.1t
Cisco>>Ios >> Version 12.1xa
Cisco>>Ios >> Version 12.1xb
Cisco>>Ios >> Version 12.1xc
Cisco>>Ios >> Version 12.1xd
Cisco>>Ios >> Version 12.1xe
Cisco>>Ios >> Version 12.1xf
Cisco>>Ios >> Version 12.1xg
Cisco>>Ios >> Version 12.1xh
Cisco>>Ios >> Version 12.1xi
Cisco>>Ios >> Version 12.1xj
Cisco>>Ios >> Version 12.1xl
Cisco>>Ios >> Version 12.1xp
References