Vulnerability Note VU#24346
Cisco IOS software vulnerable to DoS via HTTP request containing "%%"
Overview
There is a denial-of-service vulnerability in several Cisco switch and router products which allows an attacker to force affected devices to crash and reboot.
Description
A vulnerability exists in multiple versions of Cisco's Internetworking Operating System (IOS) software which allows an attacker to force affected switches and routers to crash and reboot. If the IOS HTTP interface is enabled and presented with a request for "http://router-ip/anytext/%%", the software becomes trapped in a loop until a two-minute watchdog timer expires, causing the device to restart. |
Impact
An attacker can force affected products to reboot, resulting in a denial-of-service while the device is restarting. In some situations, the device may not restart properly without manual intervention such as a power cycle. |
Solution
Apply a patch from Cisco Cisco has released an advisory to address this issue and has provided patches for affected versions of the IOS software. For further details, please consult the vendor section of this document. |
Disable the HTTP management interface
|
Systems Affected
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Cisco Systems Inc. | Vulnerable | - | 30 Mar 2004 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- VU#683677
- http://www.securityfocus.com/bid/1154
- http://www.cisco.com/warp/public/707/ioshttpserver-pub.shtml
- http://www.cisco.com/warp/public/707/cisco-sn-20040326-exploits.shtml
Credit
The CERT/CC thanks Keith Woodworth for discovering this vulnerability and Cisco for the information contained in their advisory.
This document was written by Jeffrey P. Lanza.
Other Information
- CVE IDs: CVE-2000-0380
- Date Public: 26 Apr 2000
- Date First Published: 09 Nov 2000
- Date Last Updated: 30 Mar 2004
- Severity Metric: 11.25
- Document Revision: 13
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.
This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify