{"$schema":"https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json","document":{"category":"csaf_security_advisory","csaf_version":"2.1","title":"Etherleak (CVE-2003-0001)","distribution":{"tlp":{"label":"CLEAR"}},"publisher":{"category":"vendor","name":"WatchGuard PSIRT","namespace":"https://www.watchguard.com"},"tracking":{"id":"WGSA-2026-0031","status":"final","version":"55","initial_release_date":"2026-09-11T19:48:09.334936+00:00","current_release_date":"2026-09-11T19:47:55.772839+00:00","revision_history":[{"date":"2026-09-11T19:48:09.334936+00:00","number":"55","summary":"Initial release."}]},"references":[{"summary":"vendor-advisory","url":"https://psirt.watchguard.com/WGSA-2026-0031"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2003-0001"}],"notes":[{"category":"summary","text":"Padding bytes in Ethernet packets on some Firebox models are not cleared before the data frame is created. This leaks a small amount of random information from the firewall memory into the Ethernet packets. An attacker on the same Ethernet subnet as the Firebox may be able able to collect potentially sensitive information from these packets.\n\nThis issue is also known as Etherleak and is detected by security scanners as CVE-2003-0001.","title":"Summary"}]},"product_tree":{"branches":[{"category":"vendor","name":"WatchGuard","branches":[{"category":"product_name","name":"Fireware OS (Default)","branches":[{"category":"product_version_range","name":"vers >= 12.0, < 12.12.1; vers >= 2025.0, < 2026.2.1","product":{"name":"Fireware OS (Default) vers >= 12.0, < 12.12.1; vers >= 2025.0, < 2026.2.1","product_id":"CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default"}}]}]}]},"vulnerabilities":[{"notes":[{"category":"description","text":"Padding bytes in Ethernet packets on some Firebox models are not cleared before the data frame is created. This leaks a small amount of random information from the firewall memory into the Ethernet packets. An attacker on the same Ethernet subnet as the Firebox may be able able to collect potentially sensitive information from these packets.\n\nThis issue is also known as Etherleak and is detected by security scanners as CVE-2003-0001.","title":"Summary"}],"product_status":{"known_affected":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default"]},"cve":"CVE-2003-0001","remediations":[{"category":"vendor_fix","details":"Upgrade to Fireware OS 12.12.1 or later.","product_ids":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default"]}]}]}