Lucene search

K
cveMitreCVE-2004-1112
HistoryJan 10, 2005 - 5:00 a.m.

CVE-2004-1112

2005-01-1005:00:00
mitre
web.nvd.nist.gov
24
cisco security agent
csa
buffer overflow
remote attack
bypass
vulnerability

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.005

Percentile

75.3%

The buffer overflow trigger in Cisco Security Agent (CSA) before 4.0.3 build 728 waits five minutes for a user response before terminating the process, which could allow remote attackers to bypass the buffer overflow protection by sending additional buffer overflow attacks within the five minute timeout period.

Affected configurations

Nvd
Node
ciscosecurity_agentMatch3
OR
ciscosecurity_agentMatch4.0
OR
ciscosecurity_agentMatch4.0.1
OR
ciscosecurity_agentMatch4.0.2
OR
ciscosecurity_agentMatch4.0.3
OR
okenastormwatchMatch3.x
VendorProductVersionCPE
ciscosecurity_agent3cpe:2.3:a:cisco:security_agent:3:*:*:*:*:*:*:*
ciscosecurity_agent4.0cpe:2.3:a:cisco:security_agent:4.0:*:*:*:*:*:*:*
ciscosecurity_agent4.0.1cpe:2.3:a:cisco:security_agent:4.0.1:*:*:*:*:*:*:*
ciscosecurity_agent4.0.2cpe:2.3:a:cisco:security_agent:4.0.2:*:*:*:*:*:*:*
ciscosecurity_agent4.0.3cpe:2.3:a:cisco:security_agent:4.0.3:*:*:*:*:*:*:*
okenastormwatch3.xcpe:2.3:a:okena:stormwatch:3.x:*:*:*:*:*:*:*

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.005

Percentile

75.3%

Related for CVE-2004-1112