01-10-2019 02:58 AM - edited 03-08-2019 05:00 PM
c2960x-universalk9-mz.150-2a.EX5 - current image
I am having vulnerability issue in the title of UDP IP ID zero. Can anyone help this to fix.
01-10-2019 03:53 AM
HI there,
Are you referring to this vulnerability:
https://nvd.nist.gov/vuln/detail/CVE-2002-0510
...if so, the ability to fingerprint the system isn't a major vulnerability.
cheers,
Seb.
01-10-2019 04:28 AM
okay. how to disable UDP IP ID zero in CLI?
01-10-2019 04:35 AM
It is an artifact of the network stack used internally by IOS.
Searching the Cisco Security Advisories and Alerts page for that CVE gives no results:
...which suggests that cisco didn't deem it a bug/ vulnerability.
cheers,
Seb.
01-10-2019 04:29 AM
Any cisco Bug id available?
01-10-2019 04:37 AM
There is a link to a pdf in the link Seb posted, which is a very interesting read...
The only bug I could find is the one below:
CVE-2002-0510 - ACE Linux vulnerable to UDP non-zero IP ID
CSCte37151
Description
Symptom:
ACE is vulnerable to CVE-2002-0510. Linux 2.4.x kernels keeps the IP Identification field at 0 for all
non-fragmented UDP packets
Conditions:
This can occur when connection-less udp sockets are used
Workaround:
NONE
Customer Visible
Notifications
Save Bug
Open Support Case
Was the description about this Bug Helpful?(2)
Details
Last Modified:
Jun 12,2018
Status:
Fixed
Severity:
3 Moderate
Product: (1)
Cisco ACE 4700 Series Application Control Engine Appliances
Support Cases:
3
Known Affected Releases: (1)
3.0(0)A2(1.2)
Known Fixed Releases: (1)
3.0(0)A4(1.0)
01-10-2019 06:10 AM
Thanks for update. shall i use no service udp-small-servers command.
https://www.cisco.com/c/en/us/support/docs/ip/access-lists/13608-21.html - reference link
01-10-2019 07:44 AM
That command is enabled by default in IOS >12.0 .
I don't believe issuing it will stop your vulnerability scan from picking it up. Let us know.
01-10-2019 08:06 AM
yes. So what is the command to disable?
01-10-2019 08:48 AM
Sorry, incorrect wording on my part, the command "no service udp-small-servers" is part of the default configuration on IOS >12.0
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide