{"api_version":"1","generated_at":"2026-07-24T19:34:25+00:00","cve":"CVE-2001-1533","urls":{"html":"https://cve.report/CVE-2001-1533","api":"https://cve.report/api/cve/CVE-2001-1533.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2001-1533","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2001-1533"},"summary":{"title":"CVE-2001-1533","description":"Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets.  NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability.  Therefore this \"laws of physics\" issue might not be included in CVE","state":"PUBLISHED","assigner":"mitre","published_at":"2001-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a","CWE-noinfo Not enough information"],"metrics":[{"version":"3.1","source":"ADP","type":"DECLARED","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/3501","name":"http://www.securityfocus.com/bid/3501","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft ISA Server Denial of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00018.html","name":"http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00018.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft ISA Server Fragmented Udp Flood Vulnerability","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00031.html","name":"http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00031.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"RE: Microsoft ISA Server Fragmented Udp Flood Vulnerability","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/7446.php","name":"http://www.iss.net/security_center/static/7446.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ISS X-Force Database:","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2001-1533","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2001-1533","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2001","cve_id":"1533","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"isa_server","cpe6":"2000","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T04:58:11.600Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"3501","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/3501"},{"name":"isa-udp-flood-dos(7446)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/7446.php"},{"name":"20051101 RE: Microsoft ISA Server Fragmented Udp Flood Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00031.html"},{"name":"20011102 Microsoft ISA Server Fragmented Udp Flood Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00018.html"}],"title":"CVE Program Container"},{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"}},{"other":{"content":{"id":"CVE-2001-1533","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2024-03-21T15:57:24.602314Z","version":"2.0.3"},"type":"ssvc"}}],"problemTypes":[{"descriptions":[{"description":"CWE-noinfo Not enough information","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-01-16T19:29:17.831Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets.  NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability.  Therefore this \"laws of physics\" issue might not be included in CVE"}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-07-14T04:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"3501","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/3501"},{"name":"isa-udp-flood-dos(7446)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/7446.php"},{"name":"20051101 RE: Microsoft ISA Server Fragmented Udp Flood Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00031.html"},{"name":"20011102 Microsoft ISA Server Fragmented Udp Flood Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00018.html"}],"tags":["disputed"],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2001-1533","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"** DISPUTED * Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets.  NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability.  Therefore this \"laws of physics\" issue might not be included in CVE."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"3501","refsource":"BID","url":"http://www.securityfocus.com/bid/3501"},{"name":"isa-udp-flood-dos(7446)","refsource":"XF","url":"http://www.iss.net/security_center/static/7446.php"},{"name":"20051101 RE: Microsoft ISA Server Fragmented Udp Flood Vulnerability","refsource":"BUGTRAQ","url":"http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00031.html"},{"name":"20011102 Microsoft ISA Server Fragmented Udp Flood Vulnerability","refsource":"BUGTRAQ","url":"http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00018.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2001-1533","datePublished":"2005-07-14T04:00:00.000Z","dateReserved":"2005-07-14T00:00:00.000Z","dateUpdated":"2025-01-16T19:29:17.831Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2001-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a","CWE-noinfo Not enough information"],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:isa_server:2000:*:*:*:*:*:*:*","matchCriteriaId":"80744BD9-85A9-4E33-8C35-59C8C112AC62"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2001","CveId":"1533","Ordinal":"1","Title":"CVE-2001-1533","CVE":"CVE-2001-1533","Year":"2001"},"notes":[{"CveYear":"2001","CveId":"1533","Ordinal":"1","NoteData":"Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets.  NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability.  Therefore this \"laws of physics\" issue might not be included in CVE","Type":"Description","Title":"CVE-2001-1533"},{"CveYear":"2001","CveId":"1533","Ordinal":"2","NoteData":"2005-07-14","Type":"Other","Title":"Published"}]}}}