CVE-2002-2174: Medium severity software602 602pro lan suite vulnerability
The Telnet proxy of 602Pro LAN SUITE 2002 does not restrict the number of outstanding connections to the local host, which allows remote attackers to create a denial of service (memory consumption) via a large number of connections.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the Telnet proxy in the 602Pro LAN SUITE 2002 configuration if it is not required to prevent remote attackers from creating many connections and exhausting memory.
Software602 602Pro LAN SUITE 2002 Telnet proxy enabled = false - Compensating control
Restrict access to the 602Pro LAN SUITE 2002 Telnet proxy to trusted hosts or IP ranges using firewall rules or network ACLs (deny other sources) to prevent large numbers of remote connections to the local host.
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2174?
CVE-2002-2174 is classified as a denial of service vulnerability due to memory consumption.
How do I fix CVE-2002-2174?
To fix CVE-2002-2174, restrict the number of outstanding connections in the Telnet proxy settings.
What systems are affected by CVE-2002-2174?
CVE-2002-2174 affects the 2002 version of 602Pro LAN Suite.
Can CVE-2002-2174 be exploited remotely?
Yes, CVE-2002-2174 can be exploited remotely by attackers creating numerous connections.
What type of attack does CVE-2002-2174 facilitate?
CVE-2002-2174 facilitates a denial of service attack by exhausting memory resources.