CVE-2011-2581
Summary
| CVE | CVE-2011-2581 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-09-14 16:05:23 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The ACL implementation in Cisco NX-OS 5.0(2) and 5.0(3) before 5.0(3)N2(1) on Nexus 5000 series switches, and NX-OS before 5.0(3)U1(2a) on Nexus 3000 series switches, does not properly handle comments in conjunction with deny statements, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by sending packets, aka Bug IDs CSCto09813 and CSCtr61490. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Nexus 3000 | All | All | All | All |
| Hardware | Cisco | Nexus 5000 | All | All | All | All |
| Application | Cisco | Nx-os | 5.0\(2\) | All | All | All |
| Application | Cisco | Nx-os | 5.0\(3\)n1\(1a\) | All | All | All |
| Application | Cisco | Nx-os | 5.0\(3\)n1\(1b\) | All | All | All |
| Application | Cisco | Nx-os | 5.0\(3\)n1\(1\) | All | All | All |
| Operating System | Cisco | Nx-os | 5.0\(3\) | All | All | All |
| Operating System | Cisco | Nx-os | 5.0\(3\)n1\(1c\) | All | All | All |
| Operating System | Cisco | Nx-os | 5.0\(3\)u1\(1a\) | All | All | All |
| Operating System | Cisco | Nx-os | 5.0\(3\)u1\(1b\) | All | All | All |
| Operating System | Cisco | Nx-os | 5.0\(3\)u1\(1d\) | All | All | All |
| Operating System | Cisco | Nx-os | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Nexus Series Switches ACL Deny Statement Security Bypass Security Issue - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Cisco NX-OS Nexus 3000 and 5000 Switches Let Remote Users Bypass Access Control Lists - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Cisco Security Advisory: Cisco Nexus 5000 and 3000 Series Switches Access Control List Bypass Vulnerability - Cisco Systems | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.