CVE-1999-1216: High severity Cisco router vulnerability
Cisco routers 9.17 and earlier allow remote attackers to bypass security restrictions via certain IP source routed packets that should normally be denied using the "no ip source-route" command.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable IP source routing on affected Cisco routers by configuring 'no ip source-route' (apply in global configuration or per-interface as appropriate) to deny IP source-routed packets.
Cisco Router ip source-route = no ip source-route
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1216?
CVE-1999-1216 has a high severity due to the potential for remote attackers to bypass security restrictions.
How do I fix CVE-1999-1216?
To fix CVE-1999-1216, you should disable IP source routing on the affected Cisco routers by using the 'no ip source-route' command.
Which Cisco router versions are affected by CVE-1999-1216?
CVE-1999-1216 affects Cisco routers version 9.17 and earlier, including specific versions like 8.2, 8.3, and 9.0.
What are the risk implications of CVE-1999-1216?
The risk implications of CVE-1999-1216 include unauthorized access to network resources and potential data breaches.
Is there a workaround for CVE-1999-1216?
The recommended workaround for CVE-1999-1216 is to ensure that IP source routing is disabled on all affected devices.