← Vulnerability feed

Vulnerability record · CVE-2004-1464 · published 31 December 2004

CVE-2004-1464: Cisco IOS Telnet VTY resource exhaustion denial of service

Cisco · Ios

Cisco IOS 12.2(15) and earlier fails to properly handle crafted TCP connections to the Telnet or reverse Telnet port, exhausting virtual terminal (VTY) resources. Once VTY lines are consumed, legitimate administrators can no longer open remote management sessions, leaving the device effectively unmanageable until it recovers. The flaw is a resource-consumption issue (CWE-400) rather than memory corruption or code execution.

5.9 CVSS 3.1 Medium CISA KEV since 19 May 2023 EPSS 4.8% · top 8.3% CWE-400 · Uncontrolled resource consumption
5.9CVSS 3.1 base score, v2 5.0
4.8%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
13References
16 Jun 2026Last modified by NVD

Description

Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is remotely reachable without authentication and is listed in CISA KEV, but it only causes availability loss and requires crafted traffic (AC:H), so it ranks below code-execution issues.

What it is

Cisco IOS 12.2(15) and earlier fails to properly handle crafted TCP connections to the Telnet or reverse Telnet port, exhausting virtual terminal (VTY) resources. Once VTY lines are consumed, legitimate administrators can no longer open remote management sessions, leaving the device effectively unmanageable until it recovers. The flaw is a resource-consumption issue (CWE-400) rather than memory corruption or code execution.

Impact

An unauthenticated remote attacker can deny all further VTY (Telnet) connections to the device, blocking administrative access and remote management. No confidentiality or integrity impact is described; the effect is availability loss on the affected router or switch.

Attack surface

Reachable over the network via the Telnet or reverse Telnet TCP port; the CVSS vector shows AV:N/PR:N/UI:N, so no authentication or user interaction is required. The high attack complexity (AC:H) reflects the need to craft connections in a way that reliably consumes VTY lines.

Exploitation

CVE-2004-1464 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2023-05-19), indicating observed exploitation, though no ransomware campaign use is recorded. EPSS 30-day probability is 0.0484 (91.5th percentile), and references include vendor and CERT/CC advisories plus a patch reference.

What to do

  • Upgrade Cisco IOS to a release later than 12.2(15) per the vendor advisory and CERT/CC guidance.
  • Disable Telnet and reverse Telnet where possible and restrict VTY access to trusted management networks via ACLs.
  • Apply VTY access-class filtering and transport input restrictions so only required protocols and source addresses can reach terminal lines.
  • Monitor VTY line utilization and set connection timeouts to limit the impact of resource exhaustion.
  • Where immediate upgrade is not possible, isolate management interfaces from untrusted networks.

Detection

  • Alert on sustained or bursty TCP connection attempts to Telnet/reverse Telnet ports on Cisco IOS devices.
  • Monitor VTY line usage and log messages indicating refused or failed virtual terminal connections.
  • Track authentication and connection logs for management sessions to spot exhaustion patterns preceding admin lockout.
  • Use network flow data to identify repeated short-lived connections to port 23 from single or distributed sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2004-1464 to the Known Exploited Vulnerabilities catalog on 19 May 2023 as "Cisco IOS Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 9 June 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/12395/ Broken LinkVendor Advisory
http://securitytracker.com/id?1011079 Broken LinkThird Party AdvisoryVDB Entry
http://www.cisco.com/warp/public/707/cisco-sa-20040827-telnet.shtml Not ApplicableVendor Advisory
http://www.kb.cert.org/vuls/id/384230 PatchThird Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/11060 Broken LinkThird Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/17131 Third Party AdvisoryVDB Entry
http://secunia.com/advisories/12395/ Broken LinkVendor Advisory
http://securitytracker.com/id?1011079 Broken LinkThird Party AdvisoryVDB Entry
http://www.cisco.com/warp/public/707/cisco-sa-20040827-telnet.shtml Not ApplicableVendor Advisory
http://www.kb.cert.org/vuls/id/384230 PatchThird Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/11060 Broken LinkThird Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/17131 Third Party AdvisoryVDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2004-1464 US Government Resource

Track CVE-2004-1464 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-0171Cisco IOS Smart Install improper input validation allows remote code executionCisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a bu…KEVEPSS 99%analysed9.8CVE-2017-12240Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCEThe DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 pac…KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed8.8CVE-2017-6738Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionThe SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that affects SNMP versions 1, 2c, and 3. An authenticated remote attac…KEVEPSS 11%analysed8.8CVE-2017-6739Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionCisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMP versions 1, 2c, and 3. A remote attacker who knows the SN…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2004-1464), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.