ID

VAR-200102-0055


CVE

CVE-2001-0019


TITLE

Cisco Content service Switch Very long filename service denial vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200102-037

DESCRIPTION

Arrowpoint (aka Cisco Content Services, or CSS) allows local users to cause a denial of service via a long argument to the "show script," "clear script," "show archive," "clear archive," "show log," or "clear log" commands. The Cisco Content Services (CSS) switches are hardware designed to provide enhanced web services for e-commerece and Web Content delivery using the Cisco Web Network Services (Web NS). The CSS switch is distributed by Cisco Systems. A problem in the CSS could allow a local user to deny service to legitimate users. The problem occurs in the handling of input by local users. A user must have access to the switch command line interface prior to launching an attack, but not have administrative privileges. Upon connecting to a non-privileged account, a user can locally execute a command on the switch which requires a file name as an argument. Upon specifying a filename that is the maximum size of the filename buffer, the switch reboots and starts system checks. This vulnerability makes it possible for a user with malicious intentions to connect to a switch granting sufficient privileges, and execute a command that could deny service to legitimate network users. This vulnerability affects CSS switches 11050, 11150, and 11800

Trust: 1.26

sources: NVD: CVE-2001-0019 // BID: 2330 // VULHUB: VHN-2841

AFFECTED PRODUCTS

vendor:ciscomodel:content services switchscope:eqversion:*

Trust: 1.0

vendor:ciscomodel:arrowpointscope:eqversion:*

Trust: 1.0

vendor:ciscomodel:arrowpointscope: - version: -

Trust: 0.6

vendor:ciscomodel:content services switchscope: - version: -

Trust: 0.6

vendor:ciscomodel:webnsscope:eqversion:4.0

Trust: 0.3

vendor:ciscomodel:webnsscope:eqversion:3.0

Trust: 0.3

sources: BID: 2330 // CNNVD: CNNVD-200102-037 // NVD: CVE-2001-0019

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2001-0019
value: LOW

Trust: 1.0

CNNVD: CNNVD-200102-037
value: LOW

Trust: 0.6

VULHUB: VHN-2841
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2001-0019
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-2841
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-2841 // CNNVD: CNNVD-200102-037 // NVD: CVE-2001-0019

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2001-0019

THREAT TYPE

local

Trust: 0.9

sources: BID: 2330 // CNNVD: CNNVD-200102-037

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-200102-037

EXTERNAL IDS

db:NVDid:CVE-2001-0019

Trust: 2.0

db:CNNVDid:CNNVD-200102-037

Trust: 0.7

db:CISCOid:20010131 CISCO CONTENT SERVICES SWITCH VULNERABILITY

Trust: 0.6

db:ATSTAKEid:A013101-1

Trust: 0.6

db:BIDid:2330

Trust: 0.4

db:VULHUBid:VHN-2841

Trust: 0.1

sources: VULHUB: VHN-2841 // BID: 2330 // CNNVD: CNNVD-200102-037 // NVD: CVE-2001-0019

REFERENCES

url:http://www.atstake.com/research/advisories/2001/a013101-1.txt

Trust: 2.0

url:http://www.cisco.com/warp/public/707/arrowpoint-cli-filesystem-pub.shtml

Trust: 1.7

sources: VULHUB: VHN-2841 // BID: 2330 // CNNVD: CNNVD-200102-037 // NVD: CVE-2001-0019

CREDITS

This vulnerability was announced to Bugtraq in a Cisco Security Advisory on January 31, 2001. It was initially discovered by Ollie Whitehouse <ollie@atstake.com>.

Trust: 0.9

sources: BID: 2330 // CNNVD: CNNVD-200102-037

SOURCES

db:VULHUBid:VHN-2841
db:BIDid:2330
db:CNNVDid:CNNVD-200102-037
db:NVDid:CVE-2001-0019

LAST UPDATE DATE

2024-08-14T13:08:39.389000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-2841date:2008-09-05T00:00:00
db:BIDid:2330date:2009-07-11T04:46:00
db:CNNVDid:CNNVD-200102-037date:2005-10-20T00:00:00
db:NVDid:CVE-2001-0019date:2008-09-05T20:23:03.980

SOURCES RELEASE DATE

db:VULHUBid:VHN-2841date:2001-02-12T00:00:00
db:BIDid:2330date:2001-01-31T00:00:00
db:CNNVDid:CNNVD-200102-037date:2001-02-12T00:00:00
db:NVDid:CVE-2001-0019date:2001-02-12T05:00:00