WGSA-2026-0031

Etherleak (CVE-2003-0001)

Medium Published 2026-09-11Updated 2026-09-11

Summary #

Padding bytes in Ethernet packets on some Firebox models are not cleared before the data frame is created. This leaks a small amount of random information from the firewall memory into the Ethernet packets. An attacker on the same Ethernet subnet as the Firebox may be able able to collect potentially sensitive information from these packets.

This issue is also known as Etherleak and is detected by security scanners as CVE-2003-0001.

CVE identifiers #

CVE IDDescriptionCVSS
CVE-2003-0001 Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.

Product status #

ProductAffectedNot affected
Fireware OS
Default >= 2025.0, < 2026.2.1, >= 12.0, < 12.12.1>= 2026.2.1, >= 12.12.1

Solution #

Firebox Platform

Status

Resolved Version

T20, T40, T40-CW, T25, T25-W, T45, T45-POE, T45-CW, T80, T85-POE, M290

Resolved

12.12.1, 2026.2.1

All other models

Not Affected

Workaround #

There is no workaround to prevent the information leak in the Ethernet packets; however, restricting access to the networks mitigates the risk of this issue.

References #