CVE-2001-1533
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/12/2001
Last modified:
03/04/2025
Description
Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:microsoft:isa_server:2000:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00018.html
- http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00031.html
- http://www.iss.net/security_center/static/7446.php
- http://www.securityfocus.com/bid/3501
- http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00018.html
- http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00031.html
- http://www.iss.net/security_center/static/7446.php
- http://www.securityfocus.com/bid/3501