CVE-2000-0380
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
26/04/2000
Last modified:
03/04/2025
Description
The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string.
Impact
Base Score 2.0
7.10
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:cisco:ios:11.1:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:11.2:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:11.2\(4\)f1:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:11.2\(8\):*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:11.2\(8\)p:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:11.2\(9\)p:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:11.2\(9\)xa:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:11.2\(10\):*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:11.2\(10\)bc:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:11.2\(17\):*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:11.2p:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:11.3:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:11.3\(1\):*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:11.3\(1\)ed:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:11.3\(1\)t:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://archives.neohapsis.com/archives/bugtraq/2000-04/0261.html
- http://www.cisco.com/warp/public/707/ioshttpserver-pub.shtml
- http://www.osvdb.org/1302
- http://www.securityfocus.com/bid/1154
- http://archives.neohapsis.com/archives/bugtraq/2000-04/0261.html
- http://www.cisco.com/warp/public/707/ioshttpserver-pub.shtml
- http://www.osvdb.org/1302
- http://www.securityfocus.com/bid/1154