Vulnerabilities > CVE-1999-1175 - Unspecified vulnerability in Cisco IOS

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
cisco
nessus

Summary

Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048.

Vulnerable Configurations

Part Description Count
OS
Cisco
95

Nessus

NASL familyCISCO
NASL idCISCO-SA-19980513-WCCP-AUTH.NASL
descriptionThe Web Cache Control Protocol (WCCP), available on Cisco devices, does not provide any authentication. A router configured to support Cache Engines will treat any host that sends it valid WCCP hello packets as a cache engine, and may divert HTTP traffic to that host. If a router is configured to use WCCP, an attacker can divert web traffic passing through such a router.
last seen2020-06-01
modified2020-06-02
plugin id17778
published2012-01-10
reporterThis script is Copyright (C) 2012-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/17778
titleCisco Web Cache Control Protocol Router Vulenrability