CVE-2004-2549 describes a denial-of-service vulnerability affecting Nortel Wireless LAN Access Point models 2220, 2221, and 2225. Remote attackers can crash the Telnet (port 23) and HTTP (port 80) services by sending a malformed TCP request containing a large string followed by eight newline characters, likely due to a buffer overflow. This vulnerability has a CVSS score of 5.0, indicating a medium severity with low attack complexity and no authentication required, leading to a partial availability impact. While not listed in CISA's KEV catalog, an ExploitDB entry exists (EDB-23786), suggesting public exploit code availability. There is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:nortel:wlan_access_point_2220:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:nortel:wlan_access_point_2221:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:nortel:wlan_access_point_2225:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.