PT-1997-1000 · Cisco+4 · Cisco Ios+7

CVE-1999-0667

·

Publicado

1997-09-19

·

Atualizado

2022-08-17

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS (affected versions not specified) Zyxel ZyWALL USG 300 (affected versions not specified) D-Link DSR-1000 (affected versions not specified) D-Link DSR-500 (affected versions not specified) D-Link DSR-250 (affected versions not specified) D-Link DSR-150 (affected versions not specified) FANUC 32i (affected versions not specified) Windows (affected versions not specified)
Description The issue is related to the lack of authentication for ARP packets in the affected software, which allows an attacker to conduct ARP spoofing attacks. This can lead to the interception of network traffic, IP address spoofing, or denial of service. The attacker can send fake ARP replies to poison the ARP cache, allowing them to redirect network packets to a different node. This vulnerability can be exploited to intercept and modify network services used by the affected devices.
Recommendations For Cisco IOS, consider implementing ARP packet authentication mechanisms to prevent spoofing attacks. For Zyxel ZyWALL USG 300, restrict access to the device's ARP table to minimize the risk of exploitation. For D-Link DSR-1000, D-Link DSR-500, D-Link DSR-250, and D-Link DSR-150, disable ARP packet forwarding until a patch is available. For FANUC 32i, implement network segmentation to limit the spread of spoofed ARP packets. For Windows, enable ARP packet authentication or use alternative security measures to prevent ARP spoofing attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2014-00018
BDU:2014-00217
BDU:2014-00326
BDU:2014-00328
BDU:2014-00329
BDU:2015-00094
BDU:2015-00095
BDU:2015-00096
CVE-1999-0667

Produtos afetados

Cisco Ios
Dsr-1000
Dsr-150
Dsr-250
Dsr-500
Fanuc 32I
Windows
Zywall Usg 300