CVE-2002-2185 describes a denial-of-service vulnerability affecting various operating systems, including Debian, Mandrakesoft, Microsoft, Red Hat, SGI, and SUSE. A local attacker can exploit this flaw in the Internet Group Management Protocol (IGMP) by sending a crafted IGMP membership report to a target's Ethernet address instead of the multicast group address. This manipulation causes the affected system to cease sending reports to the router, effectively disconnecting the group from the network. With a CVSS score of 4.9 (AV:L/AC:L/Au:N/C:N/I:N/A:C), this vulnerability has low attack complexity and requires local access, resulting in a complete denial of service. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.5CPE matchmatch criteria | cpe:2.3:o:sgi:irix:6.5:*:*:*:*:*:*:* | ||
6.5.1CPE matchmatch criteria | cpe:2.3:o:sgi:irix:6.5.1:*:*:*:*:*:*:* | ||
6.5.2CPE matchmatch criteria | cpe:2.3:o:sgi:irix:6.5.2:*:*:*:*:*:*:* | ||
6.5.3CPE matchmatch criteria | cpe:2.3:o:sgi:irix:6.5.3:*:*:*:*:*:*:* | ||
6.5.4CPE matchmatch criteria | cpe:2.3:o:sgi:irix:6.5.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:N/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.