{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2004-1464",
  "revision": 1,
  "title": "Cisco routers — the management lines filled up",
  "summary": "A crafted connection to the telnet port of Cisco's router software (IOS) occupies the virtual terminal lines, and further remote logins are refused. Releases 12.2(15) and earlier are affected, and other access paths go with it.",
  "source_type": "cve",
  "severity": "medium",
  "cvss": {
    "score": 5.9,
    "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "version": "3.1"
  },
  "epss": 0.0484,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "high",
    "kev_added": "2023-05-19",
    "prerequisites": "Network access to the device's telnet or reverse telnet port."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1499"
  ],
  "kill_chain": "impact",
  "recommended_action": "Move the device to a supported release, and reach management over a dedicated path with the telnet and reverse telnet ports closed to everyone else.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2004-1464",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2004-1464",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2004-1464",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2004-1464",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "http://secunia.com/advisories/12395/"
    },
    {
      "type": "vendor_advisory",
      "url": "http://www.cisco.com/warp/public/707/cisco-sa-20040827-telnet.shtml"
    },
    {
      "type": "vendor_advisory",
      "url": "http://www.kb.cert.org/vuls/id/384230"
    }
  ],
  "published_at": "2004-12-31T05:00:00.000Z",
  "issued_at": "2026-09-24T12:52:19.575Z",
  "tags": [
    "cisco",
    "ios",
    "router",
    "denial-of-service",
    "legacy",
    "kev"
  ]
}
