Link to home
Create AccountLog in
Security

Security

--

Questions

--

Followers

Top Experts

Avatar of shamnad
shamnad

High Security Vulnerability
Find below vulnerability details during a vulnerability scan thru GFI LAN Guard

OVAL:22538: A router or firewall allows source routed packets from arbitrary hosts (CVE-1999-0510)..

How to disable this "OVAL:22538: A router or firewall allows source routed packets from arbitrary hosts (CVE-1999-0510)" via group policy.

Zero AI Policy

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Avatar of Joe SpradlinJoe Spradlin🇺🇸

Are you saying that LanGuard presented those results to you?  Which scan in LanGuard were you performing?

Avatar of shamnadshamnad

ASKER

Full Vulnerability Assesment

Avatar of Joe SpradlinJoe Spradlin🇺🇸

Did the scan return any other specifics?  I know that from my experience with LanGuard, it can be a bit misleading with some of the results.  It looks to me from what you posted, that there is a machine out on your network that has a port(s) opened that allows the traffic/vulnerability.  Do you have any of your workstations / servers performing routing?  Or do you perhaps have a misconfigured firewall device?

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


Avatar of shamnadshamnad

ASKER

Almost all machines in domain have this vulnerability as per the scan from GFI as part of the PCI Scan

Avatar of Joe SpradlinJoe Spradlin🇺🇸

Ah...now that is familiar.  I would start to look at your domain machines and determine if they are running routing and remote access.  If you have an external firewall device, you can use GP to disable the workstation FW.  Are all your machines on the network patched up?  Although it does not sound like a patch issue, many security focused Microsoft patches can close those holes.

Like I said, start by taking a look at the relevant "services" running on one of the machines in question that deal with routing, etc...and rescan.

Also...it can be ok to have that vulnerability internally if you are protected in other ways.  Not all vulnerabilities reported by GFI are critical.  I went through my scan and had to turn off the parts that I know would fail due to configurations and my setup.

ASKER CERTIFIED SOLUTION
Avatar of David Johnson, CDDavid Johnson, CD🇨🇦

Link to home
membership
Log in or create a free account to see answer.
Signing up is free and takes 30 seconds. No credit card required.
Create Account

SOLUTION
Avatar of Joe SpradlinJoe Spradlin🇺🇸

Link to home
membership
Log in or create a free account to see answer.
Signing up is free and takes 30 seconds. No credit card required.

Avatar of Joe SpradlinJoe Spradlin🇺🇸

Nice David...thanks man, beat me to it  :)

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.

Security

Security

--

Questions

--

Followers

Top Experts

Security is the protection of information systems from theft or damage to the hardware, the software, and the information on them, as well as from disruption or misdirection of the services they provide. The main goal of security is protecting assets, and an asset is anything of value and worthy of protection. Information Security is a discipline of protecting information assets from threats through safeguards to achieve the objectives of confidentiality, integrity, and availability or CIA for short. On the other hand, disclosure, alteration, and disruption (DAD) compromise the security objectives.