QID 317060
Date Published: 2021-09-29
QID 317060: Cisco Internetwork Operating System (IOS) XE Software H.323 Application Level Gateway Bypass Vulnerability (cisco-sa-iosxe-h323alg-bypass-4vy2MP2Q)
A vulnerability in the H.323 application level gateway (ALG) used by the Network Address Translation (NAT) feature
of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass the ALG.
Affected Products
Cisco devices if they were running a vulnerable release of Cisco IOS XE Software, were configured for NAT, and
had the H.323 ALG enabled. The H.323 ALG is enabled by default when NAT is configured.
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
A successful exploit could allow the attacker to bypass the ALG and open connections that should not be allowed to a remote device located behind the ALG.
Customers are advised to refer to cisco-sa-iosxe-h323alg-bypass-4vy2MP2Q for more information.
- cisco-sa-iosxe-h323alg-bypass-4vy2MP2Q -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-h323alg-bypass-4vy2MP2Q
CVEs related to QID 317060
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-iosxe-h323alg-bypass-4vy2MP2Q |
|