Vulnerabilities > CVE-1999-1175 - Unspecified vulnerability in Cisco IOS
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048.
Vulnerable Configurations
Nessus
NASL family | CISCO |
NASL id | CISCO-SA-19980513-WCCP-AUTH.NASL |
description | The Web Cache Control Protocol (WCCP), available on Cisco devices, does not provide any authentication. A router configured to support Cache Engines will treat any host that sends it valid WCCP hello packets as a cache engine, and may divert HTTP traffic to that host. If a router is configured to use WCCP, an attacker can divert web traffic passing through such a router. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 17778 |
published | 2012-01-10 |
reporter | This script is Copyright (C) 2012-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/17778 |
title | Cisco Web Cache Control Protocol Router Vulenrability |