CVE-2003-1085 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 4.9% (pctl 92)
Patch early
A public exploit exists.
Description
The HTTP server in the Thomson TWC305, TWC315, and TCW690 cable modem ST42.03.0a allows remote attackers to cause a denial of service (unstable service) via a long GET request, possibly caused by a buffer overflow.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
| EPSS | 4.94% — more likely to be exploited than 92% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-12-31 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| thomson | tcm cable modem |
| thomson | tcw cable modem |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Thomson TCW690 Cable Modem ST42.03.0a - GET Denial of Service | 2005-02-19 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/014062.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/014068.html
- http://marc.info/?l=bugtraq&m=110888093214678&w=2
- http://marc.info/?l=full-disclosure&m=110880725322192&w=2
- http://secunia.com/advisories/10286
- http://secunia.com/advisories/14353
- http://www.securityfocus.com/archive/1/345414
- http://www.securityfocus.com/bid/9091
- http://www.shellsec.net/leer_advisory.php?id=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13815
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/014062.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/014068.html
- http://marc.info/?l=bugtraq&m=110888093214678&w=2
- http://marc.info/?l=full-disclosure&m=110880725322192&w=2
- http://secunia.com/advisories/10286
- http://secunia.com/advisories/14353
- http://www.securityfocus.com/archive/1/345414
- http://www.securityfocus.com/bid/9091
- http://www.shellsec.net/leer_advisory.php?id=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13815
→ the Explorer · watch your stack · NVD