CVE-2001-0929
7.5
CVSS SCORE
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
Description
Cisco IOS Firewall Feature set, aka Context Based Access Control (CBAC) or Cisco Secure Integrated Software, for IOS 11.2P through 12.2T does not properly check the IP protocol type, which could allow remote attackers to bypass access control lists.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
Low
Confidentiality
P
Integrity
P
Availability
P
Affected Software Configurations
- o cisco ios 11.2p * * * * * * *
- o cisco ios 11.3t * * * * * * *
- o cisco ios 12.0 * * * * * * *
- o cisco ios 12.0t * * * * * * *
- o cisco ios 12.1 * * * * * * *
- o cisco ios 12.1e * * * * * * *
- o cisco ios 12.1t * * * * * * *
- o cisco ios 12.2 * * * * * * *
- o cisco ios 12.2t * * * * * * *
Weaknesses (CWE)
- NVD-CWE-Other
References & External Links
- http://www.cisco.com/warp/public/707/IOS-cbac-dynacl-pub.shtml
- http://www.kb.cert.org/vuls/id/362483
- http://www.osvdb.org/808
- http://www.securityfocus.com/bid/3588
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7614
- http://www.cisco.com/warp/public/707/IOS-cbac-dynacl-pub.shtml
- http://www.kb.cert.org/vuls/id/362483
- http://www.osvdb.org/808
- http://www.securityfocus.com/bid/3588
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7614