Knowledge BaseSolutionsRemediate the vulnerability that permits Traceroute probes

Remediate the vulnerability that permits Traceroute probes

SolutionsZCF · CloudVersions4.8.xArticle IDKB-200095Updated2026-09-16

Applicable scenario

  • Product: ZCF
  • Component: Cloud
  • Version: 4.8.x
  • Deployment topology: dual management nodes
  • Trigger: A vulnerability scan reports that Traceroute probes are permitted and host-side rules are required to restrict related ICMP probe traffic.

Symptoms

  • A vulnerability scan reports a risk that permits Traceroute probes.
  • Only authorized network segments must be allowed; specified ICMP traffic from other sources must be blocked.
  • The change applies only to physical-host firewall rules.

Determination method

  1. Confirm the allowed network segment list before the change.

Sign in to view the rest of this article, plus more troubleshooting and solution know-how.

Remediate the vulnerability that permits Traceroute probes | KB-200095 | ZStack Resource Center