Cisco Catalyst 4000 series switches running CatOS 5.5.5, 6.3.5, and 7.1.2 do not always learn MAC addresses from a single initial packet, which causes unicast traffic to be broadcast across the switch and allows remote attackers to obtain sensitive network information by sniffing.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2002-2294
http://www.securityfocus.com/bid/4790
http://www.iss.net/security_center/static/9148.php
http://archives.neohapsis.com/archives/bugtraq/2002-06/0209.html
http://archives.neohapsis.com/archives/bugtraq/2002-05/0190.html