Etherleak (CVE-2003-0001)
Summary #
Padding bytes in Ethernet packets on some Firebox models are not cleared before the data frame is created. This leaks a small amount of random information from the firewall memory into the Ethernet packets. An attacker on the same Ethernet subnet as the Firebox may be able able to collect potentially sensitive information from these packets.
This issue is also known as Etherleak and is detected by security scanners as CVE-2003-0001.
CVE identifiers #
| CVE ID | Description | CVSS |
|---|---|---|
| CVE-2003-0001 | Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak. | — |
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Fireware OS | ||
| Default | >= 2025.0, < 2026.2.1, >= 12.0, < 12.12.1 | >= 2026.2.1, >= 12.12.1 |
Solution #
Firebox Platform | Status | Resolved Version |
|---|---|---|
T20, T40, T40-CW, T25, T25-W, T45, T45-POE, T45-CW, T80, T85-POE, M290 | Resolved | 12.12.1, 2026.2.1 |
All other models | Not Affected |
Workaround #
There is no workaround to prevent the information leak in the Ethernet packets; however, restricting access to the networks mitigates the risk of this issue.