CVE-1999-1175

Cisco IOS < 11.2 - Unauthenticated HTTP Traffic Redirection via WCCP Packets

Title source: llm
STIX 2.1

Description

Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048.

References (3)

Core 3
Core References
Patch, Vendor Advisory third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/i-054.shtml
Patch, Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/warp/public/770/wccpauth-pub.shtml
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/1577

Scores

EPSS 0.0168
EPSS Percentile 74.5%

Details

Status published
Products (1)
cisco/ios < 11.2
Published Dec 31, 1999
Tracked Since Feb 18, 2026