vendor:
IOS
by:
SecurityFocus
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: IOS
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2002-0231
CPE: o:cisco:ios
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Cisco routers in the AGS/MGS/CGS/AGS+, IGS, RSM, 800, ubr900, 1000, 1400, 1500, 1600, 1700, 2500, 2600, 3000, 3600, 3800, 4000, 4500, 4700, AS5200, AS5300, AS5800, 6400, 7000, 7200, ubr7200, 7500, and 12000 series, LS1010 ATM switch, Catalyst 6000 with IOS, Catalyst 2900XL LAN switch with IOS, Cisco DistributedDirector
2002
Cisco IOS Denial of Service Vulnerability
Cisco devices running IOS software may be prone to a denial of service attack if a URL containing a question mark followed by a slash (?/) is requested. The device will enter an infinite loop when supplied with a URL containing a '?/' and an enable password. Subsequently, the router will crash in two minutes after the watchdog timer has expired and will then reload. In certain cases, the device will not reload and a restart would be required in order to regain normal functionality.
Mitigation:
Set a strong enable password and disable the vulnerable service.