CVE-2001-0929
7.5
CVSS Score
High
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
Link copied!
Description
Cisco IOS Firewall Feature set, aka Context Based Access Control (CBAC) or Cisco Secure Integrated Software, for IOS 11.2P through 12.2T does not properly check the IP protocol type, which could allow remote attackers to bypass access control lists.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
Low
Confidentiality
P
Integrity
P
Availability
P
Affected Software Configurations
- o cisco ios 11.2p * * * * * * *
- o cisco ios 11.3t * * * * * * *
- o cisco ios 12.0 * * * * * * *
- o cisco ios 12.0t * * * * * * *
- o cisco ios 12.1 * * * * * * *
- o cisco ios 12.1e * * * * * * *
- o cisco ios 12.1t * * * * * * *
- o cisco ios 12.2 * * * * * * *
- o cisco ios 12.2t * * * * * * *
Weaknesses (CWE)
- NVD-CWE-Other
References & External Links
- http://www.cisco.com/warp/public/707/IOS-cbac-dynacl-pub.shtml
- http://www.kb.cert.org/vuls/id/362483
- http://www.osvdb.org/808
- http://www.securityfocus.com/bid/3588
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7614
- http://www.cisco.com/warp/public/707/IOS-cbac-dynacl-pub.shtml
- http://www.kb.cert.org/vuls/id/362483
- http://www.osvdb.org/808
- http://www.securityfocus.com/bid/3588
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7614
External Resources
CVE History Timeline
Jan 01, 2004 05:00
Initial Analysis
Oct 10, 2017 01:29
CVE Modified
May 14, 2024 01:19
CVE Modified
Nov 20, 2024 23:36
CVE Modified