{"api_version":"1","generated_at":"2026-07-23T06:04:10+00:00","cve":"CVE-2001-0929","urls":{"html":"https://cve.report/CVE-2001-0929","api":"https://cve.report/api/cve/CVE-2001-0929.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2001-0929","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2001-0929"},"summary":{"title":"CVE-2001-0929","description":"Cisco IOS Firewall Feature set, aka Context Based Access Control (CBAC) or Cisco Secure Integrated Software, for IOS 11.2P through 12.2T does not properly check the IP protocol type, which could allow remote attackers to bypass access control lists.","state":"PUBLISHED","assigner":"mitre","published_at":"2001-11-28 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/3588","name":"http://www.securityfocus.com/bid/3588","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cisco Context Based Access Control Protocol Check Bypassing Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/808","name":"http://www.osvdb.org/808","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"404 Not Found","mime":"text/html","httpstatus":"404","archivestatus":"403"},{"url":"http://www.cisco.com/warp/public/707/IOS-cbac-dynacl-pub.shtml","name":"http://www.cisco.com/warp/public/707/IOS-cbac-dynacl-pub.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Cisco - Networking, Cloud, and Cybersecurity Solutions","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7614","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7614","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/362483","name":"http://www.kb.cert.org/vuls/id/362483","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"CERT/CC Vulnerability Note VU#362483","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2001-0929","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2001-0929","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2001","cve_id":"929","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"11.2p","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"929","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"11.3t","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"929","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"929","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.0t","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"929","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"929","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.1e","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"929","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.1t","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"929","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"929","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.2t","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T04:37:06.942Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ios-cbac-bypass-acl(7614)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7614"},{"name":"VU#362483","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/362483"},{"name":"3588","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/3588"},{"name":"808","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/808"},{"name":"20011128 A Vulnerability in IOS Firewall Feature Set","tags":["vendor-advisory","x_refsource_CISCO","x_transferred"],"url":"http://www.cisco.com/warp/public/707/IOS-cbac-dynacl-pub.shtml"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2001-11-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cisco IOS Firewall Feature set, aka Context Based Access Control (CBAC) or Cisco Secure Integrated Software, for IOS 11.2P through 12.2T does not properly check the IP protocol type, which could allow remote attackers to bypass access control lists."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2009-03-02T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ios-cbac-bypass-acl(7614)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7614"},{"name":"VU#362483","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/362483"},{"name":"3588","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/3588"},{"name":"808","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/808"},{"name":"20011128 A Vulnerability in IOS Firewall Feature Set","tags":["vendor-advisory","x_refsource_CISCO"],"url":"http://www.cisco.com/warp/public/707/IOS-cbac-dynacl-pub.shtml"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2001-0929","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cisco IOS Firewall Feature set, aka Context Based Access Control (CBAC) or Cisco Secure Integrated Software, for IOS 11.2P through 12.2T does not properly check the IP protocol type, which could allow remote attackers to bypass access control lists."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ios-cbac-bypass-acl(7614)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7614"},{"name":"VU#362483","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/362483"},{"name":"3588","refsource":"BID","url":"http://www.securityfocus.com/bid/3588"},{"name":"808","refsource":"OSVDB","url":"http://www.osvdb.org/808"},{"name":"20011128 A Vulnerability in IOS Firewall Feature Set","refsource":"CISCO","url":"http://www.cisco.com/warp/public/707/IOS-cbac-dynacl-pub.shtml"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2001-0929","datePublished":"2002-06-25T04:00:00.000Z","dateReserved":"2002-01-31T00:00:00.000Z","dateUpdated":"2024-08-08T04:37:06.942Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2001-11-28 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:ios:11.2p:*:*:*:*:*:*:*","matchCriteriaId":"0DC1411B-4E7E-4F57-B025-9FE27B09C7AC"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:ios:11.3t:*:*:*:*:*:*:*","matchCriteriaId":"655BB9C1-BA90-452E-A9C8-9B1E15B99650"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:ios:12.0:*:*:*:*:*:*:*","matchCriteriaId":"8F86F790-6247-42F2-9487-3D60A2842F52"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:ios:12.0t:*:*:*:*:*:*:*","matchCriteriaId":"CA7F94E8-86FC-456B-A7BB-57953F67F754"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:ios:12.1:*:*:*:*:*:*:*","matchCriteriaId":"1F2F9EC5-EDA2-4C99-BBF1-2F2C92AACE95"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:ios:12.1e:*:*:*:*:*:*:*","matchCriteriaId":"7126E176-D739-4102-8F10-1EEB8C6A219D"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:ios:12.1t:*:*:*:*:*:*:*","matchCriteriaId":"752C3C6B-910D-4153-A162-DF255F60306B"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:ios:12.2:*:*:*:*:*:*:*","matchCriteriaId":"E4BC49F2-3DCB-45F0-9030-13F6415EE178"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:ios:12.2t:*:*:*:*:*:*:*","matchCriteriaId":"84900BB3-B49F-448A-9E04-FE423FBCCC4F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2001","CveId":"929","Ordinal":"1","Title":"CVE-2001-0929","CVE":"CVE-2001-0929","Year":"2001"},"notes":[{"CveYear":"2001","CveId":"929","Ordinal":"1","NoteData":"Cisco IOS Firewall Feature set, aka Context Based Access Control (CBAC) or Cisco Secure Integrated Software, for IOS 11.2P through 12.2T does not properly check the IP protocol type, which could allow remote attackers to bypass access control lists.","Type":"Description","Title":"CVE-2001-0929"},{"CveYear":"2001","CveId":"929","Ordinal":"2","NoteData":"2002-06-25","Type":"Other","Title":"Published"},{"CveYear":"2001","CveId":"929","Ordinal":"3","NoteData":"2009-03-01","Type":"Other","Title":"Modified"}]}}}