Security Response to CAN-1999-0524: Unblocked ICMP Packet Vulnerability
search cancel

Security Response to CAN-1999-0524: Unblocked ICMP Packet Vulnerability


Article ID: 339781


Updated On:


VMware vSphere ESXi


A security software audit warns that an ESX Server machine may have the security vulnerability described at: How can I protect my server? Does VMware have a fix for this?


VMware ESX Server 2.1.x
VMware ESX Server 2.0.x
VMware ESX Server 2.5.x


This is not in itself a serious security problem. This method of attack provides information that could help an attacker to identify other vulnerabilities, but does no direct harm.

This vulnerability relies on triggering ICMP packets (used by the ping utility, for example) that convey information about the network. VMware recommends that you install ESX Server on machines protected by a firewall, and block ICMP packets passing through the firewall in either direction.