CVE-2002-1501: Medium severity Enterasys Smartswitch Ssr8000 vulnerability
Published Apr 2, 2003
·Updated
The MPS functionality in Enterasys SSR8000 (Smart Switch Router) before firmware 8.3.0.10 allows remote attackers to cause a denial of service (crash) via multiple port scans to ports 15077 and 15078.
Affected Software
2 affected components
Enterasys Smartswitch Ssr8000=e8.2.0.0
Enterasys Smartswitch Ssr8000=e8.3.0.4
Remediation
Patch Available
Patch Available
Event History
Apr 2, 2003
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1501?
CVE-2002-1501 is classified as a denial of service vulnerability that can cause the affected systems to crash.
2
How do I fix CVE-2002-1501?
To fix CVE-2002-1501, upgrade the firmware on Enterasys SSR8000 to version 8.3.0.10 or later.
3
Which versions of Enterasys SSR8000 are affected by CVE-2002-1501?
CVE-2002-1501 affects Enterasys SSR8000 versions e8.3.0.4 and e8.2.0.0.
4
What attacks can be carried out using CVE-2002-1501?
Attackers can conduct multiple port scans against ports 15077 and 15078 to trigger a denial of service condition.
5
Is CVE-2002-1501 an exploit that requires authentication?
No, CVE-2002-1501 can be exploited remotely without any authentication.