First published: Tue Jul 13 2004(Updated: )
Enterasys XSR-1800 series Security Routers, when running firmware 7.0.0.0 and using Policy-Based Routing, allow remote attackers to cause a denial of service (crash) via a packet with the IP record route option set.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Enterasys Xsr-1805 | =7.0.0.0 | |
Enterasys XSR-1850 | =7.0.0.0 | |
Enterasys Xsr-3000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0674 is classified as a denial of service vulnerability that can cause crashes to affected routers.
CVE-2004-0674 affects Enterasys XSR-1800 series routers running firmware 7.0.0.0 and possibly the XSR-3000 series.
To mitigate CVE-2004-0674, it is recommended to upgrade the firmware of the affected Enterasys routers to a secure version.
CVE-2004-0674 enables remote attackers to trigger a denial of service attack through specially crafted packets.
Though CVE-2004-0674 was identified in 2004, devices still using the affected firmware versions remain vulnerable if not updated.