← Vulnerability feed

Vulnerability record · CVE-2002-1222 · published 28 October 2002

CVE-2002-1222: Cisco catos memory buffer overflow vulnerability

Cisco · Catos

Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP request.

7.1 CVSS 2.0 High EPSS 8.6% · top 5.1% CWE-119 · Memory buffer overflow
7.1CVSS 2.0 base score
8.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP request.

AV:N/AC:M/Au:N/C:N/I:N/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-1222 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2003-0216Cisco catos improper authentication vulnerabilityUnknown vulnerability in Cisco Catalyst 7.5(1) allows local users to bypass authentication and gain access to the enable mode without a password.EPSS 1.9%7.8CVE-2006-4775Cisco ios vulnerabilityThe VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(19) and CatOS allows remote attackers to cause a denial of service by sending a VTP update…EPSS 5.0%7.8CVE-2005-4258Cisco catalyst vulnerabilityUnspecified Cisco Catalyst Switches allow remote attackers to cause a denial of service (device crash) via an IP packet with the same source and dest…EPSS 2.1%7.8CVE-2001-0041Cisco catos vulnerabilityMemory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service via a series of failed telnet…EPSS 12%7.1CVE-2008-4963Cisco catos vulnerabilityUnspecified vulnerability in the VLAN Trunking Protocol (VTP) implementation on Cisco IOS and CatOS, when the VTP operating mode is not transparent, …EPSS 1.7%7.1CVE-2007-5651Cisco catos vulnerabilityUnspecified vulnerability in the Extensible Authentication Protocol (EAP) implementation in Cisco IOS 12.3 and 12.4 on Cisco Access Points and 1310 W…EPSS 1.8%7.1CVE-2002-1024Cisco ios vulnerabilityCisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was …EPSS 3.3%5.0CVE-2007-5134Cisco catalyst 6500 permissions and access controls vulnerabilityCisco Catalyst 6500 and Cisco 7600 series devices use 127/8 IP addresses for Ethernet Out-of-Band Channel (EOBC) internal communication, which might …EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2002-1222), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.