CVE-2004-1111: Medium severity Cisco Catalyst 7600 vulnerability
Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and other versions without the "no service dhcp" command, keep undeliverable DHCP packets in the queue instead of dropping them, which allows remote attackers to cause a denial of service (dropped traffic) via multiple undeliverable DHCP packets that exceed the input queue size.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1111?
CVE-2004-1111 has a medium severity rating as it can lead to a denial of service affecting network traffic.
How do I fix CVE-2004-1111?
To mitigate CVE-2004-1111, you can apply the "no service dhcp" command in the affected Cisco IOS configuration.
Which software versions are affected by CVE-2004-1111?
CVE-2004-1111 affects multiple Cisco IOS versions, including 12.2(14)SZ, 12.2(18)EW, and 12.2(18)SW among others.
Can CVE-2004-1111 be exploited remotely?
Yes, CVE-2004-1111 can be exploited by remote attackers to cause denial of service.
Is there a workaround for CVE-2004-1111?
The primary workaround for CVE-2004-1111 is to disable DHCP services on the affected Cisco devices.