CVE-2004-1454: Medium severity Cisco IOS vulnerability

Published Dec 31, 2004
·
Updated

Cisco IOS 12.0S, 12.2, and 12.3, with Open Shortest Path First (OSPF) enabled, allows remote attackers to cause a denial of service (device reload) via a malformed OSPF packet.

Affected Software

77 affected components
Cisco IOS=12.0\(22\)s
Cisco IOS=12.0\(22\)s4
Cisco IOS=12.0\(22\)s5
Cisco IOS=12.0\(22\)sy
Cisco IOS=12.0\(23\)sx
Cisco IOS=12.0\(23\)sz
Cisco IOS=12.2\(11\)yu
Cisco IOS=12.2\(11\)yv
Cisco IOS=12.2\(13\)zd
Cisco IOS=12.2\(13\)ze
Cisco IOS=12.2\(13\)zf
Cisco IOS=12.2\(13\)zg
Cisco IOS=12.2\(13\)zh
Cisco IOS=12.2\(14\)sz
Cisco IOS=12.2\(14\)sz1
Cisco IOS=12.2\(14\)sz2
Cisco IOS=12.2\(15\)b
Cisco IOS=12.2\(15\)bc
Cisco IOS=12.2\(15\)bc1
Cisco IOS=12.2\(15\)bx
Cisco IOS=12.2\(15\)bz
Cisco IOS=12.2\(15\)cx
Cisco IOS=12.2\(15\)mc1
Cisco IOS=12.2\(15\)t
Cisco IOS=12.2\(15\)t5
Cisco IOS=12.2\(15\)zj
Cisco IOS=12.2\(15\)zj1
Cisco IOS=12.2\(15\)zj2
Cisco IOS=12.2\(15\)zj3
Cisco IOS=12.2\(15\)zk
Cisco IOS=12.2\(15\)zl
Cisco IOS=12.2\(15\)zl1
Cisco IOS=12.2\(15\)zn
Cisco IOS=12.2\(15\)zo
Cisco IOS=12.2\(18\)ew
Cisco IOS=12.2\(18\)s
Cisco IOS=12.2\(18\)se
Cisco IOS=12.2\(18\)sv
Cisco IOS=12.2\(18\)sw
Cisco IOS=12.3
Cisco IOS=12.3\(1a\)
Cisco IOS=12.3\(2\)t3
Cisco IOS=12.3\(2\)xc1
Cisco IOS=12.3\(2\)xc2
Cisco IOS=12.3\(2\)xc3
Cisco IOS=12.3\(3e\)
Cisco IOS=12.3\(4\)eo1
Cisco IOS=12.3\(4\)t
Cisco IOS=12.3\(4\)t1
Cisco IOS=12.3\(4\)t2
Cisco IOS=12.3\(4\)t3
Cisco IOS=12.3\(4\)t4
Cisco IOS=12.3\(4\)xd
Cisco IOS=12.3\(4\)xd1
Cisco IOS=12.3\(4\)xd2
Cisco IOS=12.3\(4\)xg1
Cisco IOS=12.3\(4\)xh
Cisco IOS=12.3\(4\)xk
Cisco IOS=12.3\(4\)xq
Cisco IOS=12.3\(5\)
Cisco IOS=12.3\(5\)b1
Cisco IOS=12.3\(5a\)
Cisco IOS=12.3\(5a\)b
Cisco IOS=12.3\(5b\)
Cisco IOS=12.3\(5c\)
Cisco IOS=12.3\(6\)
Cisco IOS=12.3\(6a\)
Cisco IOS=12.3\(7\)t
Cisco IOS=12.3\(7.7\)
Cisco IOS=12.3\(9\)
Cisco IOS=12.3b
Cisco IOS=12.3bw
Cisco IOS=12.3t
Cisco IOS=12.3xa
Cisco IOS=12.3xb
Cisco IOS=12.3xc
Cisco IOS=12.3xe

Remediation

Event History

Dec 31, 2004
CVE Published
05:00 AM
Feb 13, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2004-1454?

CVE-2004-1454 is classified as a high severity vulnerability due to its potential to cause denial of service by device reload.

2

How do I fix CVE-2004-1454?

To fix CVE-2004-1454, upgrade to a fixed version of Cisco IOS that addresses this vulnerability.

3

What devices are affected by CVE-2004-1454?

CVE-2004-1454 affects multiple versions of Cisco IOS 12.0S, 12.2, and 12.3 with OSPF enabled.

4

What type of attack does CVE-2004-1454 involve?

CVE-2004-1454 involves an attack that sends a malformed OSPF packet to trigger a device reload, causing denial of service.

5

Can CVE-2004-1454 be exploited remotely?

Yes, CVE-2004-1454 can be exploited remotely, allowing attackers to trigger a denial of service from a distance.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203