First published: Mon Dec 31 2001(Updated: )
** DISPUTED * Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Security and Acceleration Server | =2000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1533 is classified as a denial of service vulnerability that may affect the availability of Microsoft ISA Server 2000.
The best way to mitigate CVE-2001-1533 is to ensure that the Microsoft ISA Server 2000 is properly configured to limit the impact of fragmented UDP packet floods.
CVE-2001-1533 affects users and organizations running Microsoft ISA Server 2000.
No, CVE-2001-1533 is a denial of service vulnerability and does not lead to full system compromise.
There is no official patch for CVE-2001-1533 due to the vendor's dispute regarding its impact.