Vulnerability record · CVE-2004-1464 · published 31 December 2004
CVE-2004-1464: Cisco IOS Telnet VTY resource exhaustion denial of service
Cisco · Ios
Cisco IOS 12.2(15) and earlier fails to properly handle crafted TCP connections to the Telnet or reverse Telnet port, exhausting virtual terminal (VTY) resources. Once VTY lines are consumed, legitimate administrators can no longer open remote management sessions, leaving the device effectively unmanageable until it recovers. The flaw is a resource-consumption issue (CWE-400) rather than memory corruption or code execution.
Description
Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityThe flaw is remotely reachable without authentication and is listed in CISA KEV, but it only causes availability loss and requires crafted traffic (AC:H), so it ranks below code-execution issues.
What it is
Cisco IOS 12.2(15) and earlier fails to properly handle crafted TCP connections to the Telnet or reverse Telnet port, exhausting virtual terminal (VTY) resources. Once VTY lines are consumed, legitimate administrators can no longer open remote management sessions, leaving the device effectively unmanageable until it recovers. The flaw is a resource-consumption issue (CWE-400) rather than memory corruption or code execution.
Impact
An unauthenticated remote attacker can deny all further VTY (Telnet) connections to the device, blocking administrative access and remote management. No confidentiality or integrity impact is described; the effect is availability loss on the affected router or switch.
Attack surface
Reachable over the network via the Telnet or reverse Telnet TCP port; the CVSS vector shows AV:N/PR:N/UI:N, so no authentication or user interaction is required. The high attack complexity (AC:H) reflects the need to craft connections in a way that reliably consumes VTY lines.
Exploitation
CVE-2004-1464 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2023-05-19), indicating observed exploitation, though no ransomware campaign use is recorded. EPSS 30-day probability is 0.0484 (91.5th percentile), and references include vendor and CERT/CC advisories plus a patch reference.
What to do
- Upgrade Cisco IOS to a release later than 12.2(15) per the vendor advisory and CERT/CC guidance.
- Disable Telnet and reverse Telnet where possible and restrict VTY access to trusted management networks via ACLs.
- Apply VTY access-class filtering and transport input restrictions so only required protocols and source addresses can reach terminal lines.
- Monitor VTY line utilization and set connection timeouts to limit the impact of resource exhaustion.
- Where immediate upgrade is not possible, isolate management interfaces from untrusted networks.
Detection
- Alert on sustained or bursty TCP connection attempts to Telnet/reverse Telnet ports on Cisco IOS devices.
- Monitor VTY line usage and log messages indicating refused or failed virtual terminal connections.
- Track authentication and connection logs for management sessions to spot exhaustion patterns preceding admin lockout.
- Use network flow data to identify repeated short-lived connections to port 23 from single or distributed sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2004-1464 to the Known Exploited Vulnerabilities catalog on 19 May 2023 as "Cisco IOS Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 9 June 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-1464 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-1464), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.