CVE-1999-0843: Medium severity Cisco router vulnerability
Denial of service in Cisco routers running NAT via a PORT command from an FTP client to a Telnet port.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable FTP active mode (PORT command) handling on the router or configure FTP endpoints to use passive mode so FTP PORT commands cannot be used to trigger NAT mappings to Telnet.
FTP (active/PORT mode) handling on Cisco routers / NAT ftp_active_mode / PORT command handling = disabled - Compensating control
Apply access-control lists or firewall rules to block FTP PORT-based NAT mappings to Telnet (TCP port 23) and restrict NAT translations so FTP control traffic cannot map client-specified ports to management services (such as Telnet).
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0843?
CVE-1999-0843 has a severity rating typically categorized as low, but it can lead to denial of service conditions.
How do I fix CVE-1999-0843?
To mitigate CVE-1999-0843, it is recommended to update your Cisco router firmware to the latest version.
What systems are affected by CVE-1999-0843?
CVE-1999-0843 affects Cisco routers that are configured to run NAT and may respond to FTP PORT commands.
What is the impact of CVE-1999-0843?
The impact of CVE-1999-0843 is a potential denial of service, which could disrupt network connectivity.
Is there a workaround for CVE-1999-0843?
A possible workaround for CVE-1999-0843 is to disable NAT on affected Cisco routers if it is not required.