CVE-1999-1582
Cisco PIX Firewall - Unintended Access Control Bypass via Established Command
Title source: llmDescription
By design, the "established" command on the Cisco PIX firewall allows connections from one host to arbitrary ports of a target host if an alternative conduit has already been allowed, which can cause administrators to configure less restrictive access controls than intended if they do not understand this functionality.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
http://www.cisco.com/warp/public/707/pixest-pub.shtml
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/8052
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/6733
Scores
EPSS
0.0188
EPSS Percentile
77.2%
Details
Status
published
Products (1)
cisco/pix_firewall
Published
Jul 15, 1998
Tracked Since
Feb 18, 2026