CVE-1999-0919: Critical severity Motorola Motorola CableRouter vulnerability
A memory leak in a Motorola CableRouter allows remote attackers to conduct a denial of service via a large number of telnet connections.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the telnet service on the Motorola Cablerouter to prevent remote telnet connections that can trigger the memory leak.
Motorola Cablerouter telnet = disabled - Compensating control
Block or restrict inbound telnet (TCP port 23) to the Motorola Cablerouter at the network perimeter (firewall/edge ACLs) and allow management access only from trusted IP addresses.
- Compensating control
Implement connection rate-limiting or session limits for telnet on upstream network devices or perimeter defenses to prevent large numbers of concurrent telnet connections that could cause a denial of service.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0919?
CVE-1999-0919 is considered to be of high severity due to its potential to cause denial of service through a memory leak.
How do I fix CVE-1999-0919?
To mitigate CVE-1999-0919, it is recommended to update the firmware of the affected Motorola CableRouter to the latest version available.
What systems are affected by CVE-1999-0919?
CVE-1999-0919 affects all models of the Motorola CableRouter that are exposed to telnet connections.
Can CVE-1999-0919 be exploited remotely?
Yes, CVE-1999-0919 can be exploited remotely by attackers who establish a large number of telnet connections.
What are the symptoms of an attack exploiting CVE-1999-0919?
Symptoms of an attack exploiting CVE-1999-0919 may include network slowdowns or complete service outages of the affected router.