ID

VAR-199904-0053


TITLE

Cisco IOS Software Input Access List Leakage with NAT

Trust: 0.3

sources: BID: 706

DESCRIPTION

It is reported that Cisco routers running versions 12.0 are affected by a vulnerability which allows packets to bypass input filter rules. When certain versions of Cisco IOS are configured with both input access lists and NAT, an interaction between different software bugs allows packets to bypass the input filter rules. This situation allows for a false sense of security by the administrators of affected devices. This may allow an attacker to circumvent access control restrictions, possibly aiding them in further compromise of protected computers.

Trust: 0.3

sources: BID: 706

AFFECTED PRODUCTS

vendor:ciscomodel:ios xgscope:eqversion:12.0.2

Trust: 0.3

vendor:ciscomodel:ios xfscope:eqversion:12.0.2

Trust: 0.3

vendor:ciscomodel:ios xdscope:eqversion:12.0.2

Trust: 0.3

vendor:ciscomodel:ios xcscope:eqversion:12.0.2

Trust: 0.3

vendor:ciscomodel:ios xescope:eqversion:12.0.1

Trust: 0.3

vendor:ciscomodel:ios xbscope:eqversion:12.0.1

Trust: 0.3

vendor:ciscomodel:ios xa3scope:eqversion:12.0.1

Trust: 0.3

vendor:ciscomodel:ios wscope:eqversion:12.0.1

Trust: 0.3

vendor:ciscomodel:ios 12.0tscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.0sscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.0dbscope: - version: -

Trust: 0.3

vendor:ciscomodel:iosscope:eqversion:12.0

Trust: 0.3

vendor:ciscomodel:ios tscope:neversion:12.0.4

Trust: 0.3

vendor:ciscomodel:ios sscope:neversion:12.0.4

Trust: 0.3

vendor:ciscomodel:iosscope:neversion:12.0.4

Trust: 0.3

vendor:ciscomodel:ios t2scope:neversion:12.0.3

Trust: 0.3

sources: BID: 706

THREAT TYPE

network

Trust: 0.3

sources: BID: 706

TYPE

Origin Validation Error

Trust: 0.3

sources: BID: 706

EXTERNAL IDS

db:BIDid:706

Trust: 0.3

sources: BID: 706

REFERENCES

url:http://www.cisco.com/warp/public/707/sec_incident_response.shtml

Trust: 0.3

sources: BID: 706

CREDITS

This vulnerability was reported to Cisco by customers. Cisco published this information in an advisory on 13 April 1999.

Trust: 0.3

sources: BID: 706

SOURCES

db:BIDid:706

LAST UPDATE DATE

2022-05-17T01:52:15.425000+00:00


SOURCES UPDATE DATE

db:BIDid:706date:1999-04-13T00:00:00

SOURCES RELEASE DATE

db:BIDid:706date:1999-04-13T00:00:00