| Vulnerability Name: | CVE-1999-1175 (CCN-1577) | ||||||||
| Assigned: | 1998-05-13 | ||||||||
| Published: | 1998-05-13 | ||||||||
| Updated: | 2017-10-10 | ||||||||
| Summary: | Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048. | ||||||||
| CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Data Manipulation | ||||||||
| References: | Source: CCN Type: CIAC Information Bulletin I-054 Cisco Web Cache Control Protocol Router Vulnerability Source: MITRE Type: CNA CVE-1999-1175 Source: CIAC Type: Patch, Vendor Advisory I-054 Source: CCN Type: Cisco Systems Field Notice, May 13, 1998 Cisco Web Cache Control Protocol Router Vulnerability Source: CISCO Type: Patch, Vendor Advisory 19980513 Cisco Web Cache Control Protocol Router Vulnerability Source: CCN Type: OSVDB ID: 6610 Cisco Cache Engine WCCP HTTP Traffic Redirection Source: XF Type: UNKNOWN cisco-wccp-vuln(1577) Source: XF Type: UNKNOWN cisco-wccp-vuln(1577) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||