LiveActive security incident?Get immediate response
CVE Record

CVE-1999-0598: A network intrusion detection system (IDS) does not properly handle packets that are sent out of order, all...

A network intrusion detection system (IDS) does not properly handle packets that are sent out of order, allowing an attacker to escape detection.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysis

Security readout for executives and security teams

This entry describes a class of weakness in network intrusion detection systems (IDS): when packets arrive out of order, the IDS may reassemble them differently than the target host does, letting an attacker slip malicious traffic past monitoring. It is a detection-evasion issue, not a direct compromise of a business system, but it undermines the visibility security teams rely on. Exposure is limited to organizations still running legacy IDS sensors that lack modern TCP reassembly and normalization. Mainstream IDS/IPS products released after the early 2000s addressed this general evasion class, so most current environments are not directly exposed, though poorly tuned or unmaintained sensors could still be blind to fragmented or reordered attacks. Low priority for executive attention. This is a historical, generic IDS evasion entry with no named product, no KEV listing, and no evidence of active exploitation. Fold any follow-up into routine detection engineering and sensor lifecycle reviews rather than incident response. Mitigation focus: Confirm IDS/IPS sensors perform full TCP stream reassembly and target-based normalization.; Keep sensor engines and signatures current; retire IDS products no longer receiving vendor updates.; Layer endpoint detection and network flow analytics so detection does not depend on one sensor..

Prepared

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-1999-0598 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
1Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.