CVE-2004-1111
Summary
| CVE | CVE-2004-1111 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-01-10 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and other versions without the "no service dhcp" command, keep undeliverable DHCP packets in the queue instead of dropping them, which allows remote attackers to cause a denial of service (dropped traffic) via multiple undeliverable DHCP packets that exceed the input queue size. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:N/I:N/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | 7200 Router | All | All | All | All |
| Hardware | Cisco | 7300 Router | All | All | All | All |
| Hardware | Cisco | 7500 Router | All | All | All | All |
| Hardware | Cisco | 7600 Router | All | All | All | All |
| Hardware | Cisco | Catalyst 7600 | All | All | sup720_msfc3 | All |
| Operating System | Cisco | Ios | 12.2\(14\)sz | All | All | All |
| Operating System | Cisco | Ios | 12.2\(18\)ew | All | All | All |
| Operating System | Cisco | Ios | 12.2\(18\)ewa | All | All | All |
| Operating System | Cisco | Ios | 12.2\(18\)s | All | All | All |
| Operating System | Cisco | Ios | 12.2\(18\)se | All | All | All |
| Operating System | Cisco | Ios | 12.2\(18\)sv | All | All | All |
| Operating System | Cisco | Ios | 12.2\(18\)sw | All | All | All |
| Operating System | Cisco | Ios | 12.2\(20\)ew | All | All | All |
| Hardware | Cisco | Multiservice Platform 2650 | All | All | All | All |
| Hardware | Cisco | Multiservice Platform 2650xm | All | All | All | All |
| Hardware | Cisco | Multiservice Platform 2651 | All | All | All | All |
| Hardware | Cisco | Multiservice Platform 2651xm | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco - Networking, Cloud, and Cybersecurity Solutions | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | |
| US-CERT Vulnerability Note VU#630104 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| www.ciac.org/ciac/bulletins/p-034.shtml | af854a3a-2127-422b-91ae-364da2661108 | www.ciac.org | |
| US-CERT Technical Cyber Security Alert TA04-316A -- Cisco IOS Input Queue Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.