CVE-2000-0380: Input Validation
The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the IOS HTTP service on affected routers and switches if it is not required.
Cisco IOS HTTP service http server = disabled - Compensating control
Restrict network access to the device HTTP service to trusted management hosts or networks (for example via ACLs, firewall rules, or management plane isolation) until a vendor fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0380?
CVE-2000-0380 is classified as a denial of service vulnerability affecting Cisco IOS devices.
How do I fix CVE-2000-0380?
To mitigate CVE-2000-0380, it is recommended to upgrade the software to a non-vulnerable version of Cisco IOS.
What versions of Cisco IOS are affected by CVE-2000-0380?
CVE-2000-0380 affects Cisco IOS versions 11.1 through 12.1.
Can CVE-2000-0380 be exploited remotely?
Yes, CVE-2000-0380 can be exploited remotely by sending a specially crafted URL containing a %% string.
What are the potential impacts of CVE-2000-0380?
Exploitation of CVE-2000-0380 may lead to a denial of service condition, causing the affected Cisco devices to become unresponsive.