VulnerabilityModified
CVE-1999-1216
Cisco routers 9.17 and earlier allow remote attackers to bypass security restrictions via certain IP source routed packets that should normally be denied using the "no ip source-route" command.
HIGH 7.5EPSS 2.08%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.08%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cisco routers 9.17 and earlier allow remote attackers to bypass security restrictions via certain IP source routed packets that should normally be denied using the "no ip source-route" command.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.08% probability · 80th percentile
- CISA KEV
- Not listed
- Affected
- cisco/router
- Source
- cve@mitre.org
References
- http://ciac.llnl.gov/ciac/bulletins/d-15.shtmlPatch, Vendor Advisory
- http://www.cert.org/advisories/CA-1993-07.htmlPatch, Third Party Advisory, US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/541
- http://ciac.llnl.gov/ciac/bulletins/d-15.shtmlPatch, Vendor Advisory
- http://www.cert.org/advisories/CA-1993-07.htmlPatch, Third Party Advisory, US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/541
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.