CVE-2003-1354 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 6.2% (pctl 93)
Patch early
A public exploit exists.
Description
Multiple GameSpy 3D 2.62 compatible gaming servers generate very large UDP responses to small requests, which allows remote attackers to use the servers as an amplifier in DDoS attacks with spoofed UDP query packets, as demonstrated using Battlefield 1942.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
| EPSS | 6.2% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| gamespy3d | gamespy 3d |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | GameSpy 3D 2.62 - Packet Amplification Denial of Service | 2003-01-17 |
References
- http://seclists.org/lists/bugtraq/2003/Jan/0178.html
- http://www.pivx.com/kristovich/adv/mk001/
- http://www.securiteam.com/securitynews/5EP0O0K8UO.html
- http://www.securityfocus.com/bid/6636
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11084
- http://seclists.org/lists/bugtraq/2003/Jan/0178.html
- http://www.pivx.com/kristovich/adv/mk001/
- http://www.securiteam.com/securitynews/5EP0O0K8UO.html
- http://www.securityfocus.com/bid/6636
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11084
→ the Explorer · watch your stack · NVD