Executive brief
A vulnerability exists in the Telnet management service of Cisco 700 series routers, which are devices used to connect small offices to the internet. An attacker can exploit this flaw to cause the router to crash or become unresponsive. This results in a loss of internet connectivity and network services for the affected location until the device is manually reset.
Technical details
A buffer overflow vulnerability exists in the Telnet daemon of Cisco 700 series (7xx) routers. The flaw is triggered by sending specially crafted data to the Telnet service, which fails to properly validate input lengths before copying them into memory buffers. A remote, unauthenticated attacker can exploit this over the network to cause a crash of the device's operating system, resulting in a denial of service (DoS). While the primary impact is availability, buffer overflows of this nature theoretically pose a risk of arbitrary code execution, though only DoS was confirmed in contemporary reports.
Affected products
- Cisco 700 series routers All versions through 1997-12-15
Timeline
- 1997-12-15: disclosed: Initial publication date in NVD