First published: Tue Jun 25 2002(Updated: )
Cisco IOS 11.1CC through 12.2 with Cisco Express Forwarding (CEF) enabled includes portions of previous packets in the padding of a MAC level packet when the MAC packet's length is less than the IP level packet length.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | =12.0st | |
Cisco IOS | =12.1e | |
Cisco IOS | =12.1t | |
Cisco IOS | =12.2t | |
Cisco IOS | =11.1cc | |
Cisco IOS | =12.0t | |
Cisco IOS | =12.1 | |
Cisco IOS | =12.0s | |
Cisco IOS | =12.2 | |
Cisco IOS | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0339 is considered a moderate severity vulnerability as it involves data leakage through padding in MAC level packets.
To mitigate CVE-2002-0339, upgrade to a Cisco IOS version that is not affected, such as 12.3 or later.
CVE-2002-0339 affects Cisco IOS versions 11.1CC through 12.2 with CEF enabled.
CVE-2002-0339 exploits the inclusion of previous packet data in the padding of MAC level packets.
A workaround for CVE-2002-0339 is to disable CEF if upgrading is not feasible, although this may impact performance.