← Vulnerability feed

Vulnerability record · CVE-2004-1111 · published 10 January 2005

CVE-2004-1111: Cisco ios vulnerability

Cisco · Ios

Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and other versions without the "no service dhcp" command, keep undeliverable DHCP packets in the queue instead of dropping them, which allows remote attackers to cause a denial of service (dropped traffic) via multiple undeliverable DHCP packets that exceed the input queue size.

5.0 CVSS 2.0 Medium EPSS 2.3% · top 17.0%
5.0CVSS 2.0 base score
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
10Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and other versions without the "no service dhcp" command, keep undeliverable DHCP packets in the queue instead of dropping them, which allows remote attackers to cause a denial of service (dropped traffic) via multiple undeliverable DHCP packets that exceed the input queue size.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-1111 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.0CVE-2012-4661Cisco adaptive security appliance software memory buffer overflow vulnerabilityStack-based buffer overflow in the DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Mod…EPSS 4.0%7.9CVE-2011-3298Cisco adaptive security appliance software improper authentication vulnerabilityCisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 be…EPSS 0.86%7.8CVE-2011-3297Cisco firewall services module software improper authentication vulnerabilityCisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7), when certain authenticat…EPSS 1.4%7.8CVE-2011-3302Cisco adaptive security appliance software vulnerabilityCisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 be…EPSS 1.7%7.8CVE-2011-3300Cisco adaptive security appliance software vulnerabilityCisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 be…EPSS 1.7%7.8CVE-2011-3303Cisco adaptive security appliance software vulnerabilityCisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 be…EPSS 1.7%7.8CVE-2011-3296Cisco firewall services module software vulnerabilityCisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7), when IPv6 is used, allow…EPSS 1.8%7.8CVE-2011-3301Cisco adaptive security appliance software vulnerabilityCisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 be…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2004-1111), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.