First published: Wed Dec 31 2003(Updated: )
Cisco IOS 12.0 through 12.2, when IP routing is disabled, accepts false ICMP redirect messages, which allows remote attackers to cause a denial of service (network routing modification).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | =12.0st | |
Cisco IOS | =12.1e | |
Cisco IOS | =12.1t | |
Cisco IOS | =12.2t | |
Cisco IOS | =12.0t | |
Cisco IOS | =12.1 | |
Cisco IOS | =12.2e | |
Cisco IOS | =12.0s | |
Cisco IOS | =12.2f | |
Cisco IOS | =12.2 | |
Cisco IOS | =12.0 | |
Cisco IOS | =12.2s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1398 is classified as a moderate severity vulnerability.
To fix CVE-2003-1398, ensure that IP routing is enabled on your Cisco IOS devices.
CVE-2003-1398 affects Cisco IOS versions 12.0 through 12.2.
Yes, CVE-2003-1398 can allow remote attackers to cause a denial of service by manipulating network routing.
CVE-2003-1398 exploits the vulnerability by accepting false ICMP redirect messages when IP routing is disabled.