Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-1999-0513

4 documents4 sources
Severity
5.0MEDIUM
EPSS
25.6%
top 3.77%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJan 5
Latest updateApr 30

Description

ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages6 packages

NVDibm/aix4 versions+3
NVDhp/hp-ux10.20, 11.00+1
NVDsun/sunos5.4, 5.5, 5.5.1+2
NVDsun/solaris4 versions+3
NVDdigital/unix6 versions+5

Also affects: Netbsd 1.2, Freebsd 1.1.5.1, 2.0.5, 2.1.0, 2.1.5, 2.1.6, 2.1.7.1, 2.2.2, 2.2.3, 2.2.4

🔴Vulnerability Details

2
GHSA
GHSA-q2cm-72c7-798h: ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service2022-04-30
CVEList
CVE-1999-0513: ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service1999-09-29

💥Exploits & PoCs

1
Exploit-DB
Linux Kernel 2.0/2.1 (Digital UNIX 4.0 D / FreeBSD 2.2.4 / HP HP-UX 10.20/11.0 / IBM AIX 3.2.5 / NetBSD 1.2 / Solaris 2.5.1) - Smurf Denial of Service1998-01-05