CVE-1999-0453: Infoleak
An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable CDP globally or on individual interfaces if CDP is not required on the device.
Cisco Router Cisco Discovery Protocol (CDP) = disabled - Compensating control
Block or restrict access to TCP port 1999 (CDP) at the network perimeter (firewall, router ACLs, or network segmentation) to prevent remote probes that can identify Cisco devices.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0453?
CVE-1999-0453 is classified as a low severity vulnerability.
How can an attacker exploit CVE-1999-0453?
An attacker can exploit CVE-1999-0453 by sending a SYN packet to port 1999 of a Cisco device.
What is affected by CVE-1999-0453?
CVE-1999-0453 affects Cisco routers that utilize the Cisco Discovery Protocol.
How can I mitigate the risks of CVE-1999-0453?
To mitigate CVE-1999-0453, consider filtering incoming traffic on port 1999.
Is CVE-1999-0453 still a concern in modern networks?
While CVE-1999-0453 is an older vulnerability, it can still pose a risk if legacy systems are in use.