Security Advisory

CVE-2001-0877

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2002-03-09 05:00:00
Last updated 2024-08-08 04:37:06
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service via (1) a spoofed SSDP advertisement that causes the client to connect to a service on another machine that generates a large amount of traffic (e.g., chargen), or (2) via a spoofed SSDP announcement to broadcast or multicast addresses, which could cause all UPnP clients to send traffic to a single target system.