Title: Cisco IOS SSH Large Packet CPU Consumption DoS
Info
Disclosure
Jun 27, 2002
Discovery
Unknown
Dates
Exploit
Feb 08, 2001
Solution
Unknown
Description
Cisco IOS contains a flaw that may allow a remote resource consumption denial of service. The issue is triggered when a device running SSH is sent a large packet designed to exploit the SSH CRC32 vulnerability in which attackers can execute arbitrary commands using an integer overflow, and will result in loss of availability for the platform.
Classification
Location:
Remote / Network Access
Attack Type:
Denial of Service,
Input Manipulation
Impact:
Loss of Availability
Exploit:
Exploit Public
Disclosure:
OSVDB Verified
Solution
Follow the instructions in the Vendor Specific Solution URL to determine the proper upgrade for the device, as this has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround(s): disable the SSH service on the device