Executive brief
A security configuration issue exists in certain network routers and firewalls that allows them to process source-routed packets. This could allow an attacker to bypass security controls or impersonate trusted systems, potentially leading to unauthorized access to internal network resources. Organizations should ensure that source routing is disabled on all perimeter and internal networking equipment.
Technical details
The affected networking devices are configured to honor IP source routing options. This vulnerability allows a remote attacker to specify the path a packet takes through the network, which can be used to bypass access control lists (ACLs), reach internal addresses that are not normally routable, or perform IP spoofing attacks by forcing return traffic through a specific gateway. The issue is a protocol-level configuration weakness rather than a software bug. Mitigation involves disabling 'ip source-route' or equivalent settings on all routing and security appliances.
Affected products
- Generic Router or Firewall
Timeline
- 1997-01-01: disclosed