← Vulnerability feed

Vulnerability record · CVE-1999-0016 · published 1 December 1997

CVE-1999-0016: Land IP Denial of Service in Multiple TCP/IP Stacks

Cisco · Ios

The Land attack is a denial-of-service condition triggered by a crafted TCP SYN packet whose source and destination IP addresses and ports are identical. Affected TCP/IP implementations in Cisco IOS, GNU inet, Microsoft Winsock, HP-UX, NetBSD, Windows 95/Windows NT, and SunOS mishandle the resulting connection state, causing the host to stall or crash. The flaw matters because it is remotely reachable without authentication and can take a system off the network with a single packet.

5.0 CVSS 2.0 Medium EPSS 96% · top 0.1%
5.0CVSS 2.0 base score
96%EPSS exploitation probability, 30 days
NoNot in CISA KEV
8Affected product versions listed by NVD
3References
16 Jun 2026Last modified by NVD

Description

Land IP denial of service.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityThe flaw is remotely exploitable without authentication and has a very high EPSS score, though it is not in CISA KEV and only causes denial of service.

What it is

The Land attack is a denial-of-service condition triggered by a crafted TCP SYN packet whose source and destination IP addresses and ports are identical. Affected TCP/IP implementations in Cisco IOS, GNU inet, Microsoft Winsock, HP-UX, NetBSD, Windows 95/Windows NT, and SunOS mishandle the resulting connection state, causing the host to stall or crash. The flaw matters because it is remotely reachable without authentication and can take a system off the network with a single packet.

Impact

An attacker can cause a denial of service, making the targeted host unresponsive or crashing its network stack. No confidentiality or integrity impact is described; the effect is availability loss.

Attack surface

Reachable over the network via a single spoofed TCP packet to a listening port; no authentication or user interaction is required. The CVSS vector AV:N/AC:L/Au:N confirms remote, low-complexity, unauthenticated exploitation.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high (0.95739, 99.869th percentile), indicating elevated predicted exploitation activity. Reference tags are empty, so no vendor or third-party confirmation of active exploitation is provided in the record.

What to do

  • Apply vendor patches or firmware updates for the affected TCP/IP stacks (Cisco IOS, HP-UX, NetBSD, SunOS, Windows 95/NT, GNU inet) as available from each vendor.
  • Enable ingress and egress filtering (BCP 38 / RFC 2827) to block packets with spoofed or invalid source addresses.
  • Configure network devices and host firewalls to drop TCP packets where source and destination IP addresses are identical.
  • Disable or restrict unnecessary network services and use TCP SYN cookies or equivalent protections where supported.
  • Retire or isolate end-of-life systems such as Windows 95, Windows NT, and SunOS that cannot be patched.

Detection

  • Monitor network traffic for TCP SYN packets with matching source and destination IP addresses and ports.
  • Alert on firewall or IDS/IPS signatures for Land attack patterns (identical src/dst IP and port).
  • Track host availability and unexpected TCP stack resets or crashes correlated with inbound SYN floods.
  • Review router and switch logs for spoofed-source packets or martian address drops.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-1999-0016 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-0171Cisco IOS Smart Install improper input validation allows remote code executionCisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a bu…KEVEPSS 99%analysed9.8CVE-2017-12240Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCEThe DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 pac…KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed9.8CVE-2012-1823PHP-CGI query string option injection enables remote code executionPHP versions before 5.3.12 and 5.4.x before 5.4.2, when run as a CGI script (php-cgi), mishandle query strings that lack an equals sign, allowing com…KEVEPSS 100%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed8.8CVE-2017-6738Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionThe SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that affects SNMP versions 1, 2c, and 3. An authenticated remote attac…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-1999-0016), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.