5
CVSSv2

CVE-2000-0984

Published: 19/12/2000 Updated: 03/05/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The HTTP server in Cisco IOS 12.0 up to and including 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a "?/" string.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios 12.0t

cisco ios 12.0w5

cisco ios 12.1db

cisco ios 12.1dc

cisco ios 12.1xf

cisco ios 12.1xg

cisco ios 12.0xh

cisco ios 12.0xj

cisco ios 12.1xa

cisco ios 12.1xb

cisco ios 12.1xc

cisco ios 12.1xj

cisco ios 12.1xl

cisco ios 12.1aa

cisco ios 12.1da

cisco ios 12.1xd

cisco ios 12.1xe

cisco ios 12.1xp

cisco ios 12.0xa

cisco ios 12.0xe

cisco ios 12.1ec

cisco ios 12.1t

cisco ios 12.1xh

cisco ios 12.1xi

Exploits

source: wwwsecurityfocuscom/bid/1838/info Cisco devices running IOS software may be prone to a denial of service attack if a URL containing a question mark followed by a slash (?/) is requested The device will enter an infinite loop when supplied with a URL containing a "?/" and an enable password Subsequently, the router will crash in ...