Vulnerability Name: | CVE-2003-0647 (CCN-12784) | ||||||||
Assigned: | 2003-07-30 | ||||||||
Published: | 2003-07-30 | ||||||||
Updated: | 2008-09-10 | ||||||||
Summary: | Buffer overflow in the HTTP server for Cisco IOS 12.2 and earlier allows remote attackers to execute arbitrary code via an extremely long (2GB) HTTP GET request. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Fri Aug 08 2003 - 12:53:00 CDT Cisco IOS HTTP remote exploit Source: MITRE Type: CNA CVE-2003-0647 Source: CCN Type: Cisco Security Notice 44226 Sending 2GB Data in GET Request Causes Buffer Overflow in Cisco IOS Software Source: CISCO Type: Patch, Vendor Advisory 20030731 Sending 2GB Data in GET Request Causes Buffer Overflow in Cisco IOS Software Source: CCN Type: US-CERT VU#579324 Cisco IOS HTTP Server vulnerable to buffer overflow when processing overly large malformed HTTP GET request Source: CERT-VN Type: Patch, Third Party Advisory, US Government Resource VU#579324 Source: CCN Type: OSVDB ID: 2342 Cisco IOS Long HTTP GET Request Overflow Source: CCN Type: BID-8373 Cisco IOS 2GB HTTP GET Buffer Overflow Vulnerability Source: XF Type: UNKNOWN cisco-ios-http-bo(12784) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |