CVE-1999-0998: Medium severity cisco cache engine vulnerability
Cisco Cache Engine allows an attacker to replace content in the cache.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Cisco Cache Engine 550from your environment.Uninstall or take the Cisco Cache Engine 550 offline if it is not required until Cisco provides an official fix.
- Compensating control
Restrict network access to the cache engine by firewall/ACLs and isolate the device on a trusted management network segment to prevent untrusted actors from reaching the cache and replacing content.
- Operational
Purge/clear the cache to remove any potentially replaced content and implement ongoing monitoring/validation of cached content integrity until a vendor patch is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0998?
CVE-1999-0998 is rated as a medium severity vulnerability.
How do I fix CVE-1999-0998?
To fix CVE-1999-0998, update Cisco Cache Engine to the latest patched version.
What type of attack can exploit CVE-1999-0998?
CVE-1999-0998 can be exploited by an attacker to replace legitimate content in the cache.
Which products are affected by CVE-1999-0998?
CVE-1999-0998 affects Cisco Cache Engine version 2.
Is CVE-1999-0998 still a concern for security?
Despite its age, CVE-1999-0998 remains a concern for systems still using the vulnerable software.