CVE-2002-1024: High severity Cisco CatOS vulnerability
Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144).
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1024?
CVE-2002-1024 has a severity rating of high due to its potential to cause denial of service by consuming CPU resources.
How do I fix CVE-2002-1024?
To mitigate CVE-2002-1024, upgrade to a Cisco IOS version that is not vulnerable, specifically versions later than 12.2.
What types of devices are affected by CVE-2002-1024?
CVE-2002-1024 affects various Cisco IOS versions, including 12.0 through 12.2, as well as certain Cisco CatOS and PIX Firewall versions.
What is the primary impact of CVE-2002-1024?
The primary impact of CVE-2002-1024 is a denial of service condition, which can lead to network downtime and interruptions.
Is there a workaround for CVE-2002-1024?
While the best solution is to update the affected systems, administrators can also implement access controls to limit exposure to the vulnerability.