CVE-1999-1466

CVSS 2.0 Score 7.5 of 10 (high)

Details

Published Dec 10, 1992
Updated: Nov 20, 2024

Summary

CVE-1999-1466 is a vulnerability affecting Cisco routers running versions 8.2 through 9.1. It allows remote attackers to bypass access control lists when extended IP access lists are used on specific interfaces, a feature known as IP route cache is enabled, and the access list incorporates the "established" keyword. This vulnerability enables unauthorized access, potentially leading to significant network security risks. Attackers can exploit this issue to traverse access control lists and gain unauthorized access to restricted areas. Organizations using the affected Cisco router versions should update to the latest software or apply patches to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco IOS

Affected Vendors

  • Cisco Systems Inc