CVE-1999-1582

Cisco PIX Firewall - Unintended Access Control Bypass via Established Command

Title source: llm
STIX 2.1

Description

By design, the "established" command on the Cisco PIX firewall allows connections from one host to arbitrary ports of a target host if an alternative conduit has already been allowed, which can cause administrators to configure less restrictive access controls than intended if they do not understand this functionality.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/warp/public/707/pixest-pub.shtml
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/8052
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/6733

Scores

EPSS 0.0188
EPSS Percentile 77.2%

Details

Status published
Products (1)
cisco/pix_firewall
Published Jul 15, 1998
Tracked Since Feb 18, 2026