CVE-1999-0843: Medium severity Cisco router vulnerability

Published Nov 4, 1999
·
Updated

Denial of service in Cisco routers running NAT via a PORT command from an FTP client to a Telnet port.

Affected Software

1 affected component
Cisco router

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable FTP active mode (PORT command) handling on the router or configure FTP endpoints to use passive mode so FTP PORT commands cannot be used to trigger NAT mappings to Telnet.

    FTP (active/PORT mode) handling on Cisco routers / NAT ftp_active_mode / PORT command handling = disabled
  2. Compensating control

    Apply access-control lists or firewall rules to block FTP PORT-based NAT mappings to Telnet (TCP port 23) and restrict NAT translations so FTP control traffic cannot map client-specified ports to management services (such as Telnet).

Event History

Nov 4, 1999
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Feb 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-1999-0843?

CVE-1999-0843 has a severity rating typically categorized as low, but it can lead to denial of service conditions.

2

How do I fix CVE-1999-0843?

To mitigate CVE-1999-0843, it is recommended to update your Cisco router firmware to the latest version.

3

What systems are affected by CVE-1999-0843?

CVE-1999-0843 affects Cisco routers that are configured to run NAT and may respond to FTP PORT commands.

4

What is the impact of CVE-1999-0843?

The impact of CVE-1999-0843 is a potential denial of service, which could disrupt network connectivity.

5

Is there a workaround for CVE-1999-0843?

A possible workaround for CVE-1999-0843 is to disable NAT on affected Cisco routers if it is not required.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203