LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2004-1464: Cisco IOS Denial-of-Service Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 19, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 9, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2004-1464 to its Known Exploited Vulnerabilities catalog on May 19, 2023, with a federal patch deadline of Jun 9, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco IOS contains an unspecified vulnerability that may block further telnet, reverse telnet, Remote Shell (RSH), Secure Shell (SSH), and in some cases, Hypertext Transport Protocol (HTTP) access to…

CVE-2004-1464 is a denial-of-service vulnerability affecting Cisco IOS. It can prevent further remote administrative access to the device over telnet, reverse telnet, Remote Shell (RSH), Secure Shell (SSH), and in some cases HTTP.

This matters to IT and security teams because loss of remote management access can leave network devices unmanageable without out-of-band or physical intervention, disrupting operations and complicating incident response until the condition is cleared.

How it works

The weakness is an unspecified vulnerability in Cisco IOS. Public detail on the exact root cause or CWE classification is limited; the observed effect is a denial-of-service condition that blocks subsequent sessions using the listed remote-access protocols.

An attacker who can reach the device may trigger the condition so that further telnet, reverse telnet, RSH, SSH, and sometimes HTTP connections are refused. Exact trigger conditions, packet sequences, or configuration prerequisites are not provided in the available summary and must be confirmed against the vendor advisory. The result is loss of remote control rather than code execution or data theft.

Am I affected? How to find it in your systems

Cisco IOS is the operating system used on many Cisco routers, switches, and related network appliances. Any device still running an affected IOS release is potentially in scope.

Telemetry signs of exploitation are primarily operational: repeated failed management connection attempts after a successful trigger, or administrators reporting lock-out of remote sessions. Confirm any suspected instance with the vendor advisory and Cisco support tools.

How to remediate

The required action is to apply updates per vendor instructions. Obtain the fixed IOS image or software release identified in the Cisco advisory for CVE-2004-1464, validate it in a test environment if possible, and schedule a controlled upgrade following your change-management process.

After patching, re-enable and test the previously affected management protocols. Review and harden remote-access configuration for this class of device: restrict management interfaces to trusted networks or management VRFs, enforce strong authentication, and disable unused protocols (for example, legacy telnet or RSH if SSH is available). Keep an accurate inventory so future IOS advisories can be assessed quickly.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These steps lower risk but do not replace the vendor update.

If your data may have been exposed

This vulnerability is described as a denial-of-service condition that blocks remote management access; known ransomware use is not documented. Actively exploited vulnerabilities can still lead to broader breaches if an attacker gains a foothold elsewhere. If you suspect compromise of accounts or systems, review logs, rotate credentials used on the affected devices, and consider running a free exposure scan of your email addresses against known breach data sets to check for previously leaked credentials.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS
Added to CISA KEVMay 19, 2023
Federal patch deadlineJun 9, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities