Cisco IOS established Access List Keyword Vulnerability
BID:315
Info
Cisco IOS established Access List Keyword Vulnerability
| Bugtraq ID: | 315 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 1999 12:00AM |
| Updated: | Jun 10 1999 12:00AM |
| Credit: | This vulnerability was reported to Cisco by a customer. |
| Vulnerable: |
Cisco IOS 11.2 |
| Not Vulnerable: | |
Discussion
Cisco IOS established Access List Keyword Vulnerability
A vulnerability in certain versions of the Cisco IOS software running in the Cisco 12000 series Gigabit Switch Routers may allow a remote attacker to bypass security restrictions.
The issue allows a vulnerable device to forward unauthorized traffic regardless of security restrictions. The issue occurs due to an error in the processing of the 'established' keyword in an access-list statement.
Specifically, this issue presents itself when an affected router carries out the following command:
access-list 101 permit tcp any any established
It is reported that the vulnerable devices ignore the 'established' keyword and forward all TCP traffic to the relevant interface.
Cisco Gigabit Switch Routers running Cisco IOS software release 11.2(14)GS2 to 11.2(15)GS3 are vulnerable to this issue.
A vulnerability in certain versions of the Cisco IOS software running in the Cisco 12000 series Gigabit Switch Routers may allow a remote attacker to bypass security restrictions.
The issue allows a vulnerable device to forward unauthorized traffic regardless of security restrictions. The issue occurs due to an error in the processing of the 'established' keyword in an access-list statement.
Specifically, this issue presents itself when an affected router carries out the following command:
access-list 101 permit tcp any any established
It is reported that the vulnerable devices ignore the 'established' keyword and forward all TCP traffic to the relevant interface.
Cisco Gigabit Switch Routers running Cisco IOS software release 11.2(14)GS2 to 11.2(15)GS3 are vulnerable to this issue.
Exploit / POC
Cisco IOS established Access List Keyword Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Cisco IOS established Access List Keyword Vulnerability
Solution:
Upgrade to Cisco IOS release 11.2(15)GS5 or later.
Solution:
Upgrade to Cisco IOS release 11.2(15)GS5 or later.
References
Cisco IOS established Access List Keyword Vulnerability
References:
References: