CVE-2001-0041 describes a memory leak vulnerability in Cisco Catalyst 4000, 5000, and 6000 series switches running Cisco CatOS. This flaw allows remote, unauthenticated attackers to trigger a denial of service by repeatedly failing Telnet authentication attempts. With a CVSS score of 7.8 (HIGH), the vulnerability is easily exploitable over the network with low complexity and no authentication, leading to a complete loss of availability. While not on the KEV catalog, exploit code is publicly available on ExploitDB, and it has garnered significant community discussion, indicating awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.5\(2\)CPE matchmatch criteria | cpe:2.3:o:cisco:catos:4.5\(2\):*:*:*:*:*:*:* | ||
4.5\(3\)CPE matchmatch criteria | cpe:2.3:o:cisco:catos:4.5\(3\):*:*:*:*:*:*:* | ||
4.5\(4\)CPE matchmatch criteria | cpe:2.3:o:cisco:catos:4.5\(4\):*:*:*:*:*:*:* | ||
4.5\(5\)CPE matchmatch criteria | cpe:2.3:o:cisco:catos:4.5\(5\):*:*:*:*:*:*:* | ||
4.5\(6\)CPE matchmatch criteria | cpe:2.3:o:cisco:catos:4.5\(6\):*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.