Cisco Access List Vulnerability
BID:53
Info
Cisco Access List Vulnerability
| Bugtraq ID: | 53 |
| Class: | Unknown |
| CVE: |
CVE-1999-1466 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 10 1992 12:00AM |
| Updated: | Jul 11 2009 12:16AM |
| Credit: | |
| Vulnerable: |
Cisco IOS 9.1 Cisco IOS 9.0 Cisco IOS 8.3 Cisco IOS 8.2 |
| Not Vulnerable: | |
Exploit / POC
Cisco Access List Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cisco Access List Vulnerability
Solution:
This vulnerability can be avoided by either rewriting the extended
access list to not use the "established" keyword, or by configuring
the interface to not use the IP route cache. To disable the IP route
cache, use the configuration command "no ip route-cache".
Example for a serial interface:
router>enable
Password:
router#configure terminal
Enter configuration commands, one per line.
Edit with DELETE, CTRL/W, and CTRL/U; end with CTRL/Z
interface serial 0
no ip route-cache
^Z
router#write memoryThis vulnerability is fixed in Cisco software releases 8.3 (update 5.10),
9.0 (update 2.5), 9.1 (update 1.1) and in all later releases. Customers
who are using software release 8.2 and do not want to upgrade to a later
release should contact Cisco's Technical Assistance Center (TAC) at
800-553-2447 (Internet: [email protected]) for more information.
The following interim releases are available via anonymous FTP from
ftp.cisco.com (131.108.1.111).
Note: this FTP server will not allow filenames to be listed or matched
with wildcards. You also cannot request the file by its full pathname.
You must first cd to the desired directory (beta83_dir, beta90_dir, or
beta91_dir) and then request the file desired (gs3-bfx.83-5.10, etc.).
Release (Update) Filename Size Checksum
8.3 (5.10) /beta83_dir/gs3-bfx.83-5.10 1234696 02465 1206
9.0 (2.5) /beta90_dir/gs3-bfx.90-2.5 1705364 47092 1666
9.1 (1.1) /beta91_dir/gs3-k.91-1.1 2005548 59407 1959
Solution:
This vulnerability can be avoided by either rewriting the extended
access list to not use the "established" keyword, or by configuring
the interface to not use the IP route cache. To disable the IP route
cache, use the configuration command "no ip route-cache".
Example for a serial interface:
router>enable
Password:
router#configure terminal
Enter configuration commands, one per line.
Edit with DELETE, CTRL/W, and CTRL/U; end with CTRL/Z
interface serial 0
no ip route-cache
^Z
router#write memoryThis vulnerability is fixed in Cisco software releases 8.3 (update 5.10),
9.0 (update 2.5), 9.1 (update 1.1) and in all later releases. Customers
who are using software release 8.2 and do not want to upgrade to a later
release should contact Cisco's Technical Assistance Center (TAC) at
800-553-2447 (Internet: [email protected]) for more information.
The following interim releases are available via anonymous FTP from
ftp.cisco.com (131.108.1.111).
Note: this FTP server will not allow filenames to be listed or matched
with wildcards. You also cannot request the file by its full pathname.
You must first cd to the desired directory (beta83_dir, beta90_dir, or
beta91_dir) and then request the file desired (gs3-bfx.83-5.10, etc.).
Release (Update) Filename Size Checksum
8.3 (5.10) /beta83_dir/gs3-bfx.83-5.10 1234696 02465 1206
9.0 (2.5) /beta90_dir/gs3-bfx.90-2.5 1705364 47092 1666
9.1 (1.1) /beta91_dir/gs3-k.91-1.1 2005548 59407 1959