Vulnerabilities > CVE-2002-2379 - Cryptographic Issues vulnerability in Cisco As5350 12.2(11T)

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
cisco
CWE-310
exploit available

Summary

Cisco AS5350 IOS 12.2(11)T with access control lists (ACLs) applied and possibly with ssh running allows remote attackers to cause a denial of service (crash) via a port scan, possibly due to an ssh bug. NOTE: this issue could not be reproduced by the vendor

Vulnerable Configurations

Part Description Count
Hardware
Cisco
1

Common Weakness Enumeration (CWE)

Common Attack Pattern Enumeration and Classification (CAPEC)

  • Signature Spoofing by Key Recreation
    An attacker obtains an authoritative or reputable signer's private signature key by exploiting a cryptographic weakness in the signature algorithm or pseudorandom number generation and then uses this key to forge signatures from the original signer to mislead a victim into performing actions that benefit the attacker.

Exploit-Db

descriptionCisco AS5350 Universal Gateway Portscan Denial Of Service Vulnerability. CVE-2002-2379 . Dos exploit for hardware platform
idEDB-ID:21971
last seen2016-02-02
modified2002-10-28
published2002-10-28
reporterThomas Munn
sourcehttps://www.exploit-db.com/download/21971/
titleCisco AS5350 - Universal Gateway Portscan Denial of Service Vulnerability