CVE-2004-1464
KEVmassRemote DoS in Cisco IOS blocks telnet, SSH, and HTTP management access
CISA: Cisco IOS Denial-of-Service Vulnerability
CVE-2004-1464 is a denial-of-service vulnerability in Cisco IOS that allows a remote attacker to make a device stop accepting new management connections. Once triggered, the device blocks further telnet, reverse telnet, Remote Shell (RSH), and SSH sessions, and in some cases HTTP access, leaving administrators unable to manage the device remotely until the condition is cleared. The CISA data does not specify the exact trigger conditions or the affected IOS version trains, but the flaw is remotely exploitable against devices that expose these management services, and it does not appear to grant code execution or data theft. Organizations running Cisco IOS routers and switches, particularly older or internet-facing devices, are affected. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 2023-05-19, indicating known exploitation in the wild; no public proof-of-concept is known, and EPSS estimates a 4.7% probability of exploitation in the next 30 days (91st percentile).
What to do: Apply IOS software updates per Cisco's instructions, as required by CISA's KEV listing (required action: apply updates per vendor instructions); consult Cisco's advisory to identify affected and fixed IOS releases for your device models. As interim mitigation, restrict telnet, reverse telnet, RSH, SSH, and HTTP management access to trusted management networks using ACLs and management-plane protection. Inventory all IOS devices, prioritize internet-facing and older-generation hardware, and monitor for symptoms such as devices refusing new management sessions.
| Cisco IOS | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Cisco IOS contains an unspecified vulnerability that may block further telnet, reverse telnet, Remote Shell (RSH), Secure Shell (SSH), and in some cases, Hypertext Transport Protocol (HTTP) access to the Cisco device.
- Affected
- Cisco IOS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Cisco
- Products
- IOS