Cisco Access Control List Fragment Keyword Ignored Vulnerability
BID:3542
Info
Cisco Access Control List Fragment Keyword Ignored Vulnerability
| Bugtraq ID: | 3542 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2001 12:00AM |
| Updated: | Nov 14 2001 12:00AM |
| Credit: | This vulnerability was first published in a Cisco Security Advisory on November 14th, 2001. |
| Vulnerable: |
Cisco IOS 12.0ST Cisco IOS 12.0S |
| Not Vulnerable: | |
Discussion
Cisco Access Control List Fragment Keyword Ignored Vulnerability
IOS is the Cisco Internet Operating System, distributed with and used on various Cisco network hardware.
A vulnerability in IOS on the 12000 series Cisco routers could make it possible for a remote user to send unauthorized traffic to a protected network. IOS does not filter packet fragments, even when the 'fragment' keyword is included in an ACL rule.
This vulnerability may result in attackers or users bypassing security policy.
IOS is the Cisco Internet Operating System, distributed with and used on various Cisco network hardware.
A vulnerability in IOS on the 12000 series Cisco routers could make it possible for a remote user to send unauthorized traffic to a protected network. IOS does not filter packet fragments, even when the 'fragment' keyword is included in an ACL rule.
This vulnerability may result in attackers or users bypassing security policy.