Security readout for executives and security teams
Plain-English summary
Older Cisco Gigabit Switch Routers running IOS had a flaw in how their access control lists handled the "established" keyword. This keyword is supposed to only allow return traffic for existing connections, but the flaw let outside attackers push unauthorized packets through the router. In business terms, a filter that was supposed to block unwanted traffic could be bypassed, weakening network segmentation on affected legacy devices.
Executive priority
Low priority for most organizations. Only relevant if legacy Cisco GSR routers remain in service. Fold review into scheduled network lifecycle and hardware refresh planning rather than emergency response.
Technical view
CVE-1999-0775 describes improper handling of the "established" keyword in access lists on Cisco Gigabit Switch Routers (GSR) running IOS. The "established" ACL primitive is intended to permit only TCP packets with ACK or RST bits set, restricting inbound flows to responses of internally initiated sessions. Due to the defect, crafted packets could traverse the filter, allowing remote attackers to forward traffic that policy intended to deny. No CVSS, CWE, or KEV entry is provided in the source bundle.
Likely exposure
Exposure today is minimal. The advisory dates to 1999–2000 and targets legacy Cisco GSR IOS platforms that are generally end-of-life. Modern IOS trains have long addressed "established" ACL behavior. Residual risk exists only where organizations still operate unpatched, unsupported GSR devices with ACL-based perimeter filtering.
Exploitation context
The provided sources do not indicate active exploitation. The CVE is not KEV-listed and no CVSS score is included. The listed X-Force reference and CVE record describe an ACL bypass rather than code execution, so historical impact was limited to policy circumvention on vulnerable Cisco GSR devices.
Researcher notes
Source bundle is sparse: no CVSS, no CWE mapping, no affected version list, and the only external reference is an IBM X-Force pointer. The CVE record lacks a specific Cisco bug ID or advisory link in the supplied bundle, so mapping to exact IOS trains requires consulting Cisco's advisory archive directly. Treat as a historical ACL-bypass class issue affecting the "established" keyword semantics on GSR platforms.
Mitigation direction
- Inventory any remaining Cisco Gigabit Switch Routers still running legacy IOS in production.
- Consult Cisco security advisories for the specific IOS train in use and apply vendor-recommended updates.
- Replace end-of-life GSR hardware with supported platforms where feasible.
- Review ACLs that rely on the 'established' keyword and supplement with stateful inspection where possible.
- Restrict management access to legacy routers via out-of-band or jump-host controls.
Validation and detection
- Identify device models and IOS versions across the routing fleet using authenticated inventory tools.
- Cross-check versions against Cisco advisories referenced from the CVE record.
- Audit ACL configurations for use of the 'established' keyword on inbound filters.
- Perform controlled traffic testing from an isolated segment to confirm ACL enforcement matches policy.
- Document findings and remediation status in the vulnerability management system.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-1999-0775 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0775CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
