CVE-2003-1398: Infoleak
Cisco IOS 12.0 through 12.2, when IP routing is disabled, accepts false ICMP redirect messages, which allows remote attackers to cause a denial of service (network routing modification).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Enable IP routing on affected Cisco IOS devices; the vulnerability occurs when IP routing is disabled, which causes the device to accept false ICMP redirect messages.
Cisco IOS ip routing = enabled - Compensating control
Filter or block ICMP Redirect messages (ICMP type 5) at the network perimeter (for example via ACLs or firewall rules) to prevent false ICMP redirect packets from reaching Cisco IOS devices.
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1398?
CVE-2003-1398 is classified as a moderate severity vulnerability.
How do I fix CVE-2003-1398?
To fix CVE-2003-1398, ensure that IP routing is enabled on your Cisco IOS devices.
Which Cisco IOS versions are affected by CVE-2003-1398?
CVE-2003-1398 affects Cisco IOS versions 12.0 through 12.2.
Can CVE-2003-1398 lead to a denial of service?
Yes, CVE-2003-1398 can allow remote attackers to cause a denial of service by manipulating network routing.
How does CVE-2003-1398 exploit the ICMP protocols?
CVE-2003-1398 exploits the vulnerability by accepting false ICMP redirect messages when IP routing is disabled.