CVE-1999-0193: Medium severity Ascend Cascadeview Ux vulnerability
Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
On the affected router (or on an immediate upstream device), configure an access-control list or packet-filter rule to drop TCP packets that contain zero-length or otherwise malformed TCP options to prevent remote-triggered reboots.
Ascend Cascadeview Ux router TCP option handling / ACL = drop TCP segments with zero-length TCP options - Compensating control
Deploy network-level filtering (perimeter firewall/IDS/WAF) to detect and drop TCP segments with zero-length TCP options and/or create IDS signatures to alert on such packets; additionally, restrict inbound traffic to the affected routers to trusted IPs where practical.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0193?
CVE-1999-0193 has a high severity rating due to its ability to cause denial of service on affected routers.
How do I fix CVE-1999-0193?
Fixing CVE-1999-0193 involves updating the affected Ascend and 3com router firmware to a version that addresses this vulnerability.
What systems are affected by CVE-1999-0193?
CVE-1999-0193 specifically affects Ascend Cascadeview UX version 1.0 routers.
What happens if CVE-1999-0193 is exploited?
Exploitation of CVE-1999-0193 can lead to the affected router being rebooted, resulting in network downtime.
Is CVE-1999-0193 a widespread issue?
While CVE-1999-0193 primarily affects older router models, it remains a concern for systems still using vulnerable configurations.