QID 317196

Date Published: 2022-10-31

QID 317196: Cisco Internetwork Operating System (IOS) Access Control List Implementation Vulnerability (cisco-sa-20011114-gsr-acl)

QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
Affected Products
Cisco 12000 Series Internet Routers
Note: This QID is not checking for the workaround.

QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.

Successful exploitation could compromise confidentiality, integrity and availability

  • CVSS V3 rated as High - 7.3 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-20011114-gsr-acl for more information.

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-20011114-gsr-acl URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20011114-gsr-acl