CVE-2001-1377
Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2.
Scoring
- CVSS base score
- 0.67
- EPSS probability
- 13.34%
- Published
- 2002-06-11
- Last modified
- 2026-03-16
Affected products
- n/a n/a