7 results (0.030 seconds)

CVSS: 7.5EPSS: 19%CPEs: 21EXPL: 1

31 Aug 2002 — Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of service (hang or memory consumption) via (1) a large packet to the DHCP port, (2) a large packet to the Telnet port, or (3) a flood of large packets to the CPE, which causes the TCP/IP stack to consume large amounts of memory. • https://www.exploit-db.com/exploits/21472 •

CVSS: 7.5EPSS: 4%CPEs: 1EXPL: 1

18 Oct 2001 — Cisco switches and routers running CBOS 2.3.8 and earlier use predictable TCP Initial Sequence Numbers (ISN), which allows remote attackers to spoof or hijack TCP connections. Conmutadores y routers Cisco corriendo CBOS 2.3.8 usan números iniciales de secuencia TCP (ISN) predecibles, lo que permite a un atacante remoto secuestrar o falsificar conexiones TCP; • https://www.exploit-db.com/exploits/19522 •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

18 Oct 2001 — Cisco CBOS 2.3.8 and earlier allows remote attackers to cause a denial of service via an ICMP ECHO REQUEST (ping) with the IP Record Route option set. Cisco CBOS 2.3.8 y anteriores permiten a atacantes remotos causar una denegación de servicio mediante un paquete ICMP de petición de eco (ping) con la opción trazar ruta activada. • http://www.cisco.com/warp/public/707/CBOS-multiple2-pub.html •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

18 Oct 2001 — Cisco CBOS 2.3.8 and earlier allows remote attackers to cause a denial of service via a series of large ICMP ECHO REPLY (ping) packets, which cause it to enter ROMMON mode and stop forwarding packets. Cisco CBOS 2.3.8 y anteriores permiten a atacantes causar una denegación de servicio mediante una serie de paquetes ICMP de petición de eco (ping) grandes, que les hacen entrar en modo ROMMON y dejar de reenviar paquetes • http://www.cisco.com/warp/public/707/CBOS-multiple2-pub.html •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

12 Oct 2001 — Cisco CBOS 2.3.8 and earlier stores the passwords for (1) exec and (2) enable in cleartext in the NVRAM and a configuration file, which could allow unauthorized users to obtain the passwords and gain privileges. • http://www.cisco.com/warp/public/707/CBOS-multiple2-pub.html •

CVSS: 9.1EPSS: 0%CPEs: 2EXPL: 0

31 Aug 2001 — Web-based configuration utility in Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap binds itself to port 80 even when web-based configuration services are disabled, which could leave the router open to attack. • http://www.cisco.com/warp/public/707/cisco-cbos-webserver-pub.shtml •

CVSS: 7.5EPSS: 5%CPEs: 15EXPL: 2

31 Aug 2001 — Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the router on the (1) HTTP or (2) telnet service, which causes the router to become unresponsive and stop forwarding packets. • https://www.exploit-db.com/exploits/21092 •