CVE-2001-0863 describes a denial-of-service vulnerability in Cisco 12000 routers running IOS 12.0 with Engine 2 line cards. The flaw stems from the router's inability to correctly process the "fragment" keyword in compiled Access Control Lists (Turbo ACLs) for packets destined for the router itself. An attacker can exploit this by sending a flood of fragmented packets, leading to a denial of service. This vulnerability is rated Medium severity with a CVSS score of 5.0. It is network-exploitable with low attack complexity and requires no authentication, but its impact is limited to availability (A:P). There is no evidence of active exploitation, and no public exploit code is available through Metasploit, Nuclei, or ExploitDB. The vulnerability has received no community discussion or media coverage, indicating a low level of public awareness and interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:cisco:12000_router:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.