Vulnerabilities in Cisco SN 5420 Storage Routers

Related Vulnerabilities: CVE-2002-1595   CVE-2002-1596   CVE-2002-1597  

Two vulnerabilities have been discovered in Cisco SN 5420 Storage Router software releases up to and including 1.1(3). One of the vulnerabilities can cause a Denial-of-Service attack. The other allows unrestricted low level access to the SN 5420. There is no workaround for these vulnerabilities. It is possible to mitigate them by blocking access to ports 513 and 8023 on the network edge. The vulnerabilities are documented in Cisco Bug IDs CSCdu27529 and CSCdu27514. No other Cisco product is affected by these vulnerabilities. This advisory is available at http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20010711-sn-kernel.