ID

VAR-199507-0003


TITLE

Cisco IOS tacacs Access List Keyword Vulnerability

Trust: 0.3

sources: BID: 703

DESCRIPTION

It is reported that Cisco IOS contains a vulnerability that may allow packets to bypass packet filtering. This vulnerability is reported to exist from version 10.3(1) to 10.3(3.3). This flaw exists in the configuration parsing code. It is triggered when the configuration contains the 'tacacs-ds' keyword. The particular circumstance by which this issue presents itself is when the IP extended access list includes the 'tacacs-ds' keyword. When versions 10.3(1) through 10.3(3.3) save their configuration, and then versions 10.3(3.4) through 10.3(4.2) of IOS read this old configuration file, the line with the 'tacacs-ds' present is incorrectly parsed and the line is ignored. An error message will be generated when the newer version of IOS reads the old configuration file. If lines containing the 'tacacs-ds' keyword are used as a part of a packet filter, the whole rule will be discarded. This leads to a false sense of security, as the administrator believes that packets will be blocked by the access control list. Attackers may then be able to bypass the access control list for the ignored configuration directive. This may allow further attacks against computers that are intended to be protected by the access control list.

Trust: 0.3

sources: BID: 703

AFFECTED PRODUCTS

vendor:ciscomodel:iosscope:eqversion:10.3.4.2

Trust: 0.3

vendor:ciscomodel:iosscope:eqversion:10.3.3.4

Trust: 0.3

vendor:ciscomodel:iosscope:neversion:10.3.4.3

Trust: 0.3

vendor:ciscomodel:iosscope:neversion:10.3.3.3

Trust: 0.3

sources: BID: 703

THREAT TYPE

network

Trust: 0.3

sources: BID: 703

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 703

EXTERNAL IDS

db:BIDid:703

Trust: 0.3

sources: BID: 703

REFERENCES

url:http://www.cisco.com/warp/public/707/sec_incident_response.shtml

Trust: 0.3

sources: BID: 703

CREDITS

This vulnerability was reported by Cisco in an advisory on 31 July 1995.

Trust: 0.3

sources: BID: 703

SOURCES

db:BIDid:703

LAST UPDATE DATE

2022-05-17T02:12:13.291000+00:00


SOURCES UPDATE DATE

db:BIDid:703date:1995-07-31T00:00:00

SOURCES RELEASE DATE

db:BIDid:703date:1995-07-31T00:00:00