First published: Tue Dec 31 2002(Updated: )
Cisco Catalyst 4000 series switches running CatOS 5.5.5, 6.3.5, and 7.1.2 do not always learn MAC addresses from a single initial packet, which causes unicast traffic to be broadcast across the switch and allows remote attackers to obtain sensitive network information by sniffing.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco CatOS | =7.1\(2\) | |
Cisco CatOS | =6.3\(5\) | |
Cisco CatOS | =5.5\(5\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2316 is considered a moderate vulnerability due to potential exposure of sensitive network information.
To fix CVE-2002-2316, upgrade to a more secure version of Cisco CatOS that addresses this MAC address learning issue.
CVE-2002-2316 affects Cisco CatOS versions 5.5.5, 6.3.5, and 7.1.2.
CVE-2002-2316 exploits the failure of Cisco Catalyst switches to learn MAC addresses from a single initial packet, causing unicast traffic to be broadcast.
Yes, CVE-2002-2316 can allow remote attackers to sniff network traffic and potentially capture sensitive information.