ID

VAR-200210-0004


CVE

CVE-2002-1222


TITLE

Cisco CatOS CiscoView HTTP Server Buffer Overflow Vulnerability

Trust: 0.9

sources: BID: 5976 // CNNVD: CNNVD-200210-286

DESCRIPTION

Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP request. Certain versions of Cisco CatOS ship with an embedded HTTP server. This issue is reported to affect CatOS versions 5.4 through 7.4 which contain "cv" in the image name

Trust: 1.26

sources: NVD: CVE-2002-1222 // BID: 5976 // VULHUB: VHN-5607

AFFECTED PRODUCTS

vendor:ciscomodel:catosscope:eqversion:5.5

Trust: 2.2

vendor:ciscomodel:catosscope:eqversion:7.4

Trust: 1.9

vendor:ciscomodel:catosscope:eqversion:7.3

Trust: 1.9

vendor:ciscomodel:catosscope:eqversion:6.1

Trust: 1.9

vendor:ciscomodel:catosscope:eqversion:5.4

Trust: 1.9

vendor:ciscomodel:catosscope:eqversion:5.5\(13a\)

Trust: 1.6

vendor:ciscomodel:catosscope:eqversion:6.1\(2\)

Trust: 1.6

vendor:ciscomodel:catosscope:eqversion:6.1(2)

Trust: 0.3

vendor:ciscomodel:catosscope:neversion:7.4(1)

Trust: 0.3

vendor:ciscomodel:catosscope:neversion:7.4(0.63)

Trust: 0.3

vendor:ciscomodel:catosscope:neversion:6.3(9)

Trust: 0.3

vendor:ciscomodel:catosscope:neversion:6.3(8.3)

Trust: 0.3

sources: BID: 5976 // CNNVD: CNNVD-200210-286 // NVD: CVE-2002-1222

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-1222
value: HIGH

Trust: 1.0

CNNVD: CNNVD-200210-286
value: HIGH

Trust: 0.6

VULHUB: VHN-5607
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2002-1222
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-5607
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-5607 // CNNVD: CNNVD-200210-286 // NVD: CVE-2002-1222

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.1

sources: VULHUB: VHN-5607 // NVD: CVE-2002-1222

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200210-286

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-200210-286

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-5607

EXTERNAL IDS

db:BIDid:5976

Trust: 2.0

db:NVDid:CVE-2002-1222

Trust: 2.0

db:CNNVDid:CNNVD-200210-286

Trust: 0.7

db:CISCOid:20021016 CISCO CATOS EMBEDDED HTTP SERVER BUFFER OVERFLOW

Trust: 0.6

db:XFid:10382

Trust: 0.6

db:EXPLOIT-DBid:21944

Trust: 0.1

db:SEEBUGid:SSVID-75759

Trust: 0.1

db:VULHUBid:VHN-5607

Trust: 0.1

sources: VULHUB: VHN-5607 // BID: 5976 // CNNVD: CNNVD-200210-286 // NVD: CVE-2002-1222

REFERENCES

url:http://www.securityfocus.com/bid/5976

Trust: 1.7

url:http://www.cisco.com/warp/public/707/catos-http-overflow-vuln.shtml

Trust: 1.7

url:http://www.iss.net/security_center/static/10382.php

Trust: 1.7

sources: VULHUB: VHN-5607 // CNNVD: CNNVD-200210-286 // NVD: CVE-2002-1222

CREDITS

Vulnerability announced in a Cisco Security Advisory.

Trust: 0.9

sources: BID: 5976 // CNNVD: CNNVD-200210-286

SOURCES

db:VULHUBid:VHN-5607
db:BIDid:5976
db:CNNVDid:CNNVD-200210-286
db:NVDid:CVE-2002-1222

LAST UPDATE DATE

2024-08-14T13:40:35.538000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-5607date:2008-09-10T00:00:00
db:BIDid:5976date:2009-07-11T18:06:00
db:CNNVDid:CNNVD-200210-286date:2005-05-13T00:00:00
db:NVDid:CVE-2002-1222date:2008-09-10T19:14:04.743

SOURCES RELEASE DATE

db:VULHUBid:VHN-5607date:2002-10-28T00:00:00
db:BIDid:5976date:2002-10-16T00:00:00
db:CNNVDid:CNNVD-200210-286date:2002-10-28T00:00:00
db:NVDid:CVE-2002-1222date:2002-10-28T05:00:00