Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048.
References
Link | Resource |
---|---|
http://www.ciac.org/ciac/bulletins/i-054.shtml | Patch Vendor Advisory |
http://www.cisco.com/warp/public/770/wccpauth-pub.shtml | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/1577 | |
http://www.ciac.org/ciac/bulletins/i-054.shtml | Patch Vendor Advisory |
http://www.cisco.com/warp/public/770/wccpauth-pub.shtml | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/1577 |
Configurations
History
20 Nov 2024, 23:30
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.ciac.org/ciac/bulletins/i-054.shtml - Patch, Vendor Advisory | |
References | () http://www.cisco.com/warp/public/770/wccpauth-pub.shtml - Patch, Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/1577 - |
Information
Published : 1999-12-31 05:00
Updated : 2024-11-20 23:30
NVD link : CVE-1999-1175
Mitre link : CVE-1999-1175
CVE.ORG link : CVE-1999-1175
JSON object : View
Products Affected
cisco
- ios
CWE