ZeroHour

CVE-2004-1464

KEVmass

Remote DoS in Cisco IOS blocks telnet, SSH, and HTTP management access

CISA: Cisco IOS Denial-of-Service Vulnerability

CVSS
EPSS
5%p92
Published
KEV added
AI analysis

CVE-2004-1464 is a denial-of-service vulnerability in Cisco IOS that allows a remote attacker to make a device stop accepting new management connections. Once triggered, the device blocks further telnet, reverse telnet, Remote Shell (RSH), and SSH sessions, and in some cases HTTP access, leaving administrators unable to manage the device remotely until the condition is cleared. The CISA data does not specify the exact trigger conditions or the affected IOS version trains, but the flaw is remotely exploitable against devices that expose these management services, and it does not appear to grant code execution or data theft. Organizations running Cisco IOS routers and switches, particularly older or internet-facing devices, are affected. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 2023-05-19, indicating known exploitation in the wild; no public proof-of-concept is known, and EPSS estimates a 4.7% probability of exploitation in the next 30 days (91st percentile).

What to do: Apply IOS software updates per Cisco's instructions, as required by CISA's KEV listing (required action: apply updates per vendor instructions); consult Cisco's advisory to identify affected and fixed IOS releases for your device models. As interim mitigation, restrict telnet, reverse telnet, RSH, SSH, and HTTP management access to trusted management networks using ACLs and management-plane protection. Inventory all IOS devices, prioritize internet-facing and older-generation hardware, and monitor for symptoms such as devices refusing new management sessions.

Affected
Cisco IOS
Estimated exposure
mass≈ hundreds of thousands of internet-exposed IOS devices, out of millions of IOS deployments overall — Cisco IOS is one of the most widely deployed network operating systems, running on millions of enterprise routers and switches, and public internet scan data historically shows on the order of hundreds of thousands of IOS devices exposing…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Cisco IOS contains an unspecified vulnerability that may block further telnet, reverse telnet, Remote Shell (RSH), Secure Shell (SSH), and in some cases, Hypertext Transport Protocol (HTTP) access to the Cisco device.

CISA Known Exploited Vulnerability
Affected
Cisco IOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Cisco
Products
IOS

In the news