Cisco Context Based Access Control Protocol Check Bypassing Vulnerability
BID:3588
Info
Cisco Context Based Access Control Protocol Check Bypassing Vulnerability
| Bugtraq ID: | 3588 |
| Class: | Design Error |
| CVE: |
CVE-2001-0929 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 28 2001 12:00AM |
| Updated: | Jul 13 2006 08:13PM |
| Credit: | This vulnerability was announced in a Cisco Security Advisory on November 28, 2001. |
| Vulnerable: |
Cisco IOS 12.2XQ Cisco IOS 12.2XK Cisco IOS 12.2XJ Cisco IOS 12.2XI Cisco IOS 12.2XH Cisco IOS 12.2XE Cisco IOS 12.2XD Cisco IOS 12.2T Cisco IOS 12.2DD Cisco IOS 12.2 Cisco IOS 12.1YF Cisco IOS 12.1YE Cisco IOS 12.1YC Cisco IOS 12.1YB Cisco IOS 12.1XT Cisco IOS 12.1XP Cisco IOS 12.1XM Cisco IOS 12.1XL Cisco IOS 12.1XK Cisco IOS 12.1XJ Cisco IOS 12.1XI Cisco IOS 12.1XH Cisco IOS 12.1XG Cisco IOS 12.1XF Cisco IOS 12.1XC Cisco IOS 12.1XB Cisco IOS 12.1T Cisco IOS 12.1E Cisco IOS 12.1 Cisco IOS 12.0XV Cisco IOS 12.0XR Cisco IOS 12.0XQ Cisco IOS 12.0XM Cisco IOS 12.0XK Cisco IOS 12.0XI Cisco IOS 12.0XG Cisco IOS 12.0XE Cisco IOS 12.0XD Cisco IOS 12.0XC Cisco IOS 12.0XB Cisco IOS 12.0XA Cisco IOS 12.0T Cisco IOS 11.3T Cisco IOS 11.2P |
| Not Vulnerable: |
Cisco IOS 12.2(8)T Cisco IOS 12.2(6) Cisco IOS 12.2(5.7)T Cisco IOS 12.2(2)XQ2 Cisco IOS 12.2(2)XK5 Cisco IOS 12.2(2)XJ1 Cisco IOS 12.2(2)XI1 Cisco IOS 12.2(2)XD3 Cisco IOS 12.2(2)XD3 Cisco IOS 12.1(9.6)E Cisco IOS 12.1(8a)E5 Cisco IOS 12.1(5)YF3 Cisco IOS 12.1(5)YE4 Cisco IOS 12.1(5)YC2 Cisco IOS 12.1(5)YB5 Cisco IOS 12.1(5)XM6 Cisco IOS 12.1(12) Cisco IOS 12.1(11a) Cisco IOS 12.1(11.1) Cisco IOS 12.1(10)E Cisco IOS 12.0(21) Cisco IOS 12.0(20.3) |
Discussion
Cisco Context Based Access Control Protocol Check Bypassing Vulnerability
IOS is a Cisco Internetwork Operating System. It is maintained and distributed by Cisco, and used on various types of Cisco hardware.
A problem has been found in the checking of protocol by the system. The vulnerable version of IOS does not check the protocol type of the packets, thus making it possible for a system on either end of the connection to send data of a different type. One such instance would be a system on the protected network sending a UDP packet to a system outside of the protected network, and the external system returning a connection to the host via TCP using the pre-established IP address and port numbers.
This could allow a remote user to gather intelligence about a host, and potentially lead to an organized attack against network resources.
IOS is a Cisco Internetwork Operating System. It is maintained and distributed by Cisco, and used on various types of Cisco hardware.
A problem has been found in the checking of protocol by the system. The vulnerable version of IOS does not check the protocol type of the packets, thus making it possible for a system on either end of the connection to send data of a different type. One such instance would be a system on the protected network sending a UDP packet to a system outside of the protected network, and the external system returning a connection to the host via TCP using the pre-established IP address and port numbers.
This could allow a remote user to gather intelligence about a host, and potentially lead to an organized attack against network resources.
References
Cisco Context Based Access Control Protocol Check Bypassing Vulnerability
References:
References: