CVE-2002-0339: Medium severity cisco ios vulnerability
Published Jun 25, 2002
·Updated
Cisco IOS 11.1CC through 12.2 with Cisco Express Forwarding (CEF) enabled includes portions of previous packets in the padding of a MAC level packet when the MAC packet's length is less than the IP level packet length.
Affected Software
10 affected components
Cisco IOS=11.1cc
Cisco IOS=12.0
Cisco IOS=12.0s
Cisco IOS=12.0st
Cisco IOS=12.0t
Cisco IOS=12.1
Cisco IOS=12.1e
Cisco IOS=12.1t
Cisco IOS=12.2
Cisco IOS=12.2t
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jun 25, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0339?
CVE-2002-0339 is considered a moderate severity vulnerability as it involves data leakage through padding in MAC level packets.
2
How do I fix CVE-2002-0339?
To mitigate CVE-2002-0339, upgrade to a Cisco IOS version that is not affected, such as 12.3 or later.
3
What versions of Cisco IOS are affected by CVE-2002-0339?
CVE-2002-0339 affects Cisco IOS versions 11.1CC through 12.2 with CEF enabled.
4
What does CVE-2002-0339 vulnerability exploit?
CVE-2002-0339 exploits the inclusion of previous packet data in the padding of MAC level packets.
5
Is there a workaround for CVE-2002-0339?
A workaround for CVE-2002-0339 is to disable CEF if upgrading is not feasible, although this may impact performance.