Cisco Context Based Access Control Protocol Check Bypassing Vulnerability

BID:3588

Info

Cisco Context Based Access Control Protocol Check Bypassing Vulnerability

Bugtraq ID: 3588
Class: Design Error
CVE: CVE-2001-0929
Remote: Yes
Local: No
Published: Nov 28 2001 12:00AM
Updated: Jul 13 2006 08:13PM
Credit: This vulnerability was announced in a Cisco Security Advisory on November 28, 2001.
Vulnerable: Cisco IOS 12.2XQ
Cisco IOS 12.2XK
Cisco IOS 12.2XJ
Cisco IOS 12.2XI
Cisco IOS 12.2XH
Cisco IOS 12.2XE
Cisco IOS 12.2XD
Cisco IOS 12.2T
Cisco IOS 12.2DD
Cisco IOS 12.2
Cisco IOS 12.1YF
Cisco IOS 12.1YE
Cisco IOS 12.1YC
Cisco IOS 12.1YB
Cisco IOS 12.1XT
Cisco IOS 12.1XP
Cisco IOS 12.1XM
Cisco IOS 12.1XL
Cisco IOS 12.1XK
Cisco IOS 12.1XJ
Cisco IOS 12.1XI
Cisco IOS 12.1XH
Cisco IOS 12.1XG
Cisco IOS 12.1XF
Cisco IOS 12.1XC
Cisco IOS 12.1XB
Cisco IOS 12.1T
Cisco IOS 12.1E
Cisco IOS 12.1
Cisco IOS 12.0XV
Cisco IOS 12.0XR
Cisco IOS 12.0XQ
Cisco IOS 12.0XM
Cisco IOS 12.0XK
Cisco IOS 12.0XI
Cisco IOS 12.0XG
Cisco IOS 12.0XE
Cisco IOS 12.0XD
Cisco IOS 12.0XC
Cisco IOS 12.0XB
Cisco IOS 12.0XA
Cisco IOS 12.0T
Cisco IOS 11.3T
Cisco IOS 11.2P
Not Vulnerable: Cisco IOS 12.2(8)T
Cisco IOS 12.2(6)
Cisco IOS 12.2(5.7)T
Cisco IOS 12.2(2)XQ2
Cisco IOS 12.2(2)XK5
Cisco IOS 12.2(2)XJ1
Cisco IOS 12.2(2)XI1
Cisco IOS 12.2(2)XD3
Cisco IOS 12.2(2)XD3
Cisco IOS 12.1(9.6)E
Cisco IOS 12.1(8a)E5
Cisco IOS 12.1(5)YF3
Cisco IOS 12.1(5)YE4
Cisco IOS 12.1(5)YC2
Cisco IOS 12.1(5)YB5
Cisco IOS 12.1(5)XM6
Cisco IOS 12.1(12)
Cisco IOS 12.1(11a)
Cisco IOS 12.1(11.1)
Cisco IOS 12.1(10)E
Cisco IOS 12.0(21)
Cisco IOS 12.0(20.3)

Discussion

Cisco Context Based Access Control Protocol Check Bypassing Vulnerability

IOS is a Cisco Internetwork Operating System. It is maintained and distributed by Cisco, and used on various types of Cisco hardware.

A problem has been found in the checking of protocol by the system. The vulnerable version of IOS does not check the protocol type of the packets, thus making it possible for a system on either end of the connection to send data of a different type. One such instance would be a system on the protected network sending a UDP packet to a system outside of the protected network, and the external system returning a connection to the host via TCP using the pre-established IP address and port numbers.

This could allow a remote user to gather intelligence about a host, and potentially lead to an organized attack against network resources.

References

Cisco Context Based Access Control Protocol Check Bypassing Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report