Junglewise Threat Intelligence

CVE-1999-0550: Generic Router information disclosure in routing tables

CVE-1999-0550 · Severity: high · CVSS 7.5 · Published 1997-01-01

Technologies: Firmware. Vendors: Generic.

Executive brief

A vulnerability in certain network routers allows unauthorized individuals to remotely view the device's routing tables. This information reveals the internal structure of a network, which can be used by attackers to map out sensitive systems or intercept network traffic. This exposure compromises the overall security and privacy of the organization's network infrastructure.

Technical details

This vulnerability involves an information disclosure flaw where a router's routing tables are accessible to arbitrary remote hosts. The root cause is typically an insecure default configuration or a lack of access control on management protocols (such as SNMP or RIP) that allow unauthenticated network queries. An attacker can exploit this by sending specific requests to the router over the network without needing prior authentication. Successful exploitation allows the attacker to retrieve the full routing table, facilitating network reconnaissance, traffic redirection, or further targeted attacks against internal network segments.

Affected products

  • Generic Router Firmware

Timeline

  • 1997-01-01: disclosed

References

Related threats