Cisco IOS established Access List Keyword Vulnerability

BID:315

Info

Cisco IOS established Access List Keyword Vulnerability

Bugtraq ID: 315
Class: Unknown
CVE:
Remote: Yes
Local: No
Published: Jun 10 1999 12:00AM
Updated: Jun 10 1999 12:00AM
Credit: This vulnerability was reported to Cisco by a customer.
Vulnerable: Cisco IOS 11.2
Not Vulnerable:

Discussion

Cisco IOS established Access List Keyword Vulnerability

A vulnerability in certain versions of the Cisco IOS software running in the Cisco 12000 series Gigabit Switch Routers may allow a remote attacker to bypass security restrictions.

The issue allows a vulnerable device to forward unauthorized traffic regardless of security restrictions. The issue occurs due to an error in the processing of the 'established' keyword in an access-list statement.

Specifically, this issue presents itself when an affected router carries out the following command:

access-list 101 permit tcp any any established

It is reported that the vulnerable devices ignore the 'established' keyword and forward all TCP traffic to the relevant interface.

Cisco Gigabit Switch Routers running Cisco IOS software release 11.2(14)GS2 to 11.2(15)GS3 are vulnerable to this issue.

Exploit / POC

Cisco IOS established Access List Keyword Vulnerability

No exploit is required.

Solution / Fix

Cisco IOS established Access List Keyword Vulnerability

Solution:
Upgrade to Cisco IOS release 11.2(15)GS5 or later.

References

Cisco IOS established Access List Keyword Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report