CVE-2001-0669 Details
Description
Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, (4) Snort before 1.8.1, (5) ISS RealSecure Network Sensor 5.x and 6.x before XPU 3.2, and (6) ISS RealSecure Server Sensor 5.5 and 6.0 for Windows, allow remote attackers to evade detection of HTTP attacks via non-standard "%u" Unicode encoding of ASCII characters in the requested URL.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://marc.info/?l=bugtraq&m=99972950200602&w=2 | CVE | |
| http://www.cisco.com/warp/public/707/cisco-intrusion-detection-obfuscation-vuln-pub.shtml | CVE | PatchVendor Advisory |
| http://www.kb.cert.org/vuls/id/548515 | CVE | US Government Resource |
| http://www.securityfocus.com/bid/3292 | CVE | |
| http://xforce.iss.net/alerts/advise95.php | CVE | PatchVendor Advisory |
| http://marc.info/?l=bugtraq&m=99972950200602&w=2 | [email protected] | |
| http://www.cisco.com/warp/public/707/cisco-intrusion-detection-obfuscation-vuln-pub.shtml | [email protected] | PatchVendor Advisory |
| http://www.kb.cert.org/vuls/id/548515 | [email protected] | US Government Resource |
| http://www.securityfocus.com/bid/3292 | [email protected] | |
| http://xforce.iss.net/alerts/advise95.php | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco catalyst 6000 intrusion detection system module | All versions |
CPE
Remediation
| |
| cisco secure intrusion detection system | All versions |
CPE
Remediation
| |
| iss realsecure network sensor | 5.x 6.x |
CPE
Remediation
| |
| iss realsecure server sensor | 5.5 6.0 |
CPE
Remediation
| |
| snort snort | 1.8.1 |
CPE
Remediation
| |
| enterasys dragon | 4.x |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Apr 16, 2026 | [email protected] | |
| Nov 20, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 18, 2016 | CVE Modified | [email protected] |
| Jan 1, 2004 | Initial Analysis | [email protected] |