ID

VAR-200201-0021


CVE

CVE-2002-1596


TITLE

Cisco SN 5420 Storage Router vulnerable to DoS via HTTP request containing long headers

Trust: 0.8

sources: CERT/CC: VU#968187

DESCRIPTION

Cisco SN 5420 Storage Router 1.1(5) and earlier allows remote attackers to cause a denial of service (router crash) via an HTTP request with large headers. The router must be restarted to regain normal functionality. Cisco has identified this issue as bug number CSCdu32533

Trust: 1.98

sources: NVD: CVE-2002-1596 // CERT/CC: VU#968187 // BID: 3834 // VULHUB: VHN-5981

AFFECTED PRODUCTS

vendor:ciscomodel:sn 5420 storage routerscope:eqversion:1.1\(3\)

Trust: 2.2

vendor:ciscomodel:sn 5420 storage routerscope:eqversion:1.1\(4\)

Trust: 2.2

vendor:ciscomodel:sn 5420 storage routerscope:eqversion:1.1\(2\)

Trust: 2.2

vendor:ciscomodel:sn 5420 storage routerscope:eqversion:1.1\(5\)

Trust: 2.2

vendor:ciscomodel: - scope: - version: -

Trust: 0.8

vendor:ciscomodel:sn storage routerscope:eqversion:54201.1(5)

Trust: 0.3

vendor:ciscomodel:sn storage routerscope:eqversion:54201.1(4)

Trust: 0.3

vendor:ciscomodel:sn storage routerscope:eqversion:54201.1(3)

Trust: 0.3

vendor:ciscomodel:sn storage routerscope:eqversion:54201.1(2)

Trust: 0.3

vendor:ciscomodel:sn storage routerscope:neversion:54201.1(7)

Trust: 0.3

sources: CERT/CC: VU#968187 // BID: 3834 // CNNVD: CNNVD-200201-003 // NVD: CVE-2002-1596

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-1596
value: MEDIUM

Trust: 1.0

CARNEGIE MELLON: VU#968187
value: 5.63

Trust: 0.8

CNNVD: CNNVD-200201-003
value: MEDIUM

Trust: 0.6

VULHUB: VHN-5981
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2002-1596
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-5981
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CERT/CC: VU#968187 // VULHUB: VHN-5981 // CNNVD: CNNVD-200201-003 // NVD: CVE-2002-1596

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-1596

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200201-003

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-200201-003

EXTERNAL IDS

db:BIDid:3834

Trust: 2.8

db:CERT/CCid:VU#968187

Trust: 2.5

db:NVDid:CVE-2002-1596

Trust: 1.7

db:CNNVDid:CNNVD-200201-003

Trust: 0.7

db:CISCOid:20020109 MULTIPLE VULNERABILITIES IN CISCO SN 5420 STORAGE ROUTERS

Trust: 0.6

db:XFid:7829

Trust: 0.6

db:VULHUBid:VHN-5981

Trust: 0.1

sources: CERT/CC: VU#968187 // VULHUB: VHN-5981 // BID: 3834 // CNNVD: CNNVD-200201-003 // NVD: CVE-2002-1596

REFERENCES

url:http://www.cisco.com/warp/public/707/sn-multiple-pub.shtml

Trust: 3.5

url:http://www.securityfocus.com/bid/3834

Trust: 3.5

url:http://www.kb.cert.org/vuls/id/968187

Trust: 2.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/7829

Trust: 2.1

url:http://xforce.iss.net/xforce/xfdb/7829

Trust: 0.6

sources: CERT/CC: VU#968187 // VULHUB: VHN-5981 // CNNVD: CNNVD-200201-003 // NVD: CVE-2002-1596

CREDITS

Cisco PSIRT※ psirt@cisco.com

Trust: 0.6

sources: CNNVD: CNNVD-200201-003

SOURCES

db:CERT/CCid:VU#968187
db:VULHUBid:VHN-5981
db:BIDid:3834
db:CNNVDid:CNNVD-200201-003
db:NVDid:CVE-2002-1596

LAST UPDATE DATE

2024-11-22T22:59:28.894000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#968187date:2002-01-14T00:00:00
db:VULHUBid:VHN-5981date:2018-10-30T00:00:00
db:BIDid:3834date:2002-01-09T00:00:00
db:CNNVDid:CNNVD-200201-003date:2005-10-20T00:00:00
db:NVDid:CVE-2002-1596date:2024-11-20T23:41:40.953

SOURCES RELEASE DATE

db:CERT/CCid:VU#968187date:2002-01-14T00:00:00
db:VULHUBid:VHN-5981date:2002-01-09T00:00:00
db:BIDid:3834date:2002-01-09T00:00:00
db:CNNVDid:CNNVD-200201-003date:2002-01-09T00:00:00
db:NVDid:CVE-2002-1596date:2002-01-09T05:00:00