CVE-1999-0159: Low severity Cisco IOS vulnerability
Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login). This applies to some IOS 9.x, 10.x, and 11.x releases.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
On affected devices, restrict interactive login access to console/VTY/management interfaces to only trusted hosts (for example by applying access-lists/access-class to VTY lines) or disable remote management if it is not required.
Cisco IOS management access (console/VTY) = restrict to trusted IPs / disable remote access if not required - Compensating control
Prevent untrusted network access to device interactive prompts by enforcing network-level controls: block or limit management-plane ports at the firewall/edge, place devices behind management VLANs, and allow access only from trusted administration hosts or networks.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0159?
CVE-1999-0159 has a significant severity as it can crash Cisco IOS devices under specific conditions.
How do I fix CVE-1999-0159?
To mitigate CVE-1999-0159, upgrade your Cisco IOS version to a release that is not affected by this vulnerability.
What versions of Cisco IOS are vulnerable to CVE-1999-0159?
CVE-1999-0159 affects Cisco IOS versions 9.x, 10.x, and some 11.x releases.
What types of devices are impacted by CVE-1999-0159?
CVE-1999-0159 can affect any Cisco device running the vulnerable versions of Cisco IOS.
Can CVE-1999-0159 be exploited remotely?
Exploitation of CVE-1999-0159 requires local access to an interactive prompt on the affected Cisco device.