CVE-1999-1582: High severity Cisco PIX firewall vulnerability
By design, the "established" command on the Cisco PIX firewall allows connections from one host to arbitrary ports of a target host if an alternative conduit has already been allowed, which can cause administrators to configure less restrictive access controls than intended if they do not understand this functionality.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Do not use the 'established' command in Cisco PIX configurations. Remove or replace any rules that use 'established' and instead create explicit access controls that limit allowed destination ports so an existing conduit cannot be used to reach arbitrary ports.
Cisco PIX established command = avoid/remove - Operational
Audit Cisco PIX firewall configurations for any use of the 'established' command and update those rules to explicit, port-restricted access rules. Verify and test changes to ensure they enforce the intended restrictions.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1582?
CVE-1999-1582 is rated as a moderate severity vulnerability due to the potential for unauthorized connections through misconfigured access controls.
How do I fix CVE-1999-1582?
To fix CVE-1999-1582, review and tighten the access control configurations on the Cisco PIX firewall to ensure they align with intended security policies.
What versions of Cisco PIX firewall are affected by CVE-1999-1582?
CVE-1999-1582 affects all versions of the Cisco PIX firewall, including the Cisco PIX 501.
What impact does CVE-1999-1582 have on Cisco PIX firewalls?
The impact of CVE-1999-1582 is that it allows unauthorized connections, potentially leading to data breaches if access controls are not properly managed.
Is there a workaround for CVE-1999-1582?
A possible workaround for CVE-1999-1582 is to implement stricter access control lists that limit the scope of allowed connections.