ID

VAR-200010-0080


CVE

CVE-2000-0700


TITLE

Cisco Gigabit Switch Routers (GSR) Forward packet vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200010-085

DESCRIPTION

Cisco Gigabit Switch Routers (GSR) with Fast Ethernet / Gigabit Ethernet cards, from IOS versions 11.2(15)GS1A up to 11.2(19)GS0.2 and some versions of 12.0, do not properly handle line card failures, which allows remote attackers to bypass ACLs or force the interface to stop forwarding packets. This could lead to exploitation of vulnerabilities that would normally have been protected by the access control lists. It may also be possible for an attacker to cause an interface on the target GSR to stop forwarding packets, resulting in a denial of service. The evasion of ACLs has to do with optimizations in handling of various packet types and occurs only on the affected interfaces. All versions of IOS greater than 11.2 on GSRs are assumed to be vulnerable

Trust: 1.26

sources: NVD: CVE-2000-0700 // BID: 1541 // VULHUB: VHN-2277

AFFECTED PRODUCTS

vendor:ciscomodel:iosscope:eqversion:12.0

Trust: 1.9

vendor:ciscomodel:iosscope:eqversion:11.3

Trust: 1.9

vendor:ciscomodel:iosscope:eqversion:11.2

Trust: 1.9

vendor:ciscomodel:iosscope:eqversion:12.0\(3\)

Trust: 1.6

vendor:ciscomodel:iosscope:eqversion:11.2\(8\)

Trust: 1.6

vendor:ciscomodel:iosscope:eqversion:11.2p

Trust: 1.6

vendor:ciscomodel:iosscope:eqversion:12.0\(2\)

Trust: 1.6

vendor:ciscomodel:iosscope:eqversion:11.3\(1\)

Trust: 1.6

vendor:ciscomodel:iosscope:eqversion:11.2\(10\)

Trust: 1.6

vendor:ciscomodel:iosscope:eqversion:12.0\(1\)

Trust: 1.6

vendor:ciscomodel:iosscope:eqversion:12.1

Trust: 1.3

vendor:ciscomodel:iosscope:eqversion:12.0\(5\)

Trust: 1.0

vendor:ciscomodel:iosscope:eqversion:12.0\(6\)

Trust: 1.0

vendor:ciscomodel:gigabit switch router 12008scope:eqversion:*

Trust: 1.0

vendor:ciscomodel:gigabit switch router 12016scope:eqversion:*

Trust: 1.0

vendor:ciscomodel:iosscope:eqversion:12.0\(4\)

Trust: 1.0

vendor:ciscomodel:iosscope:eqversion:12.0\(7\)t

Trust: 1.0

vendor:ciscomodel:gigabit switch router 12012scope:eqversion:*

Trust: 1.0

vendor:ciscomodel:ios 12.0 scscope:neversion: -

Trust: 0.6

vendor:ciscomodel:ios 12.0 sscope:neversion: -

Trust: 0.6

vendor:ciscomodel:iosscope:eqversion:12.0.7

Trust: 0.3

vendor:ciscomodel:iosscope:eqversion:12.0.6

Trust: 0.3

vendor:ciscomodel:iosscope:eqversion:12.0.5

Trust: 0.3

vendor:ciscomodel:iosscope:eqversion:12.0.4

Trust: 0.3

vendor:ciscomodel:iosscope:eqversion:12.0.3

Trust: 0.3

vendor:ciscomodel:iosscope:eqversion:12.0.2

Trust: 0.3

vendor:ciscomodel:iosscope:eqversion:12.0.1

Trust: 0.3

vendor:ciscomodel:iosscope:eqversion:11.3.1

Trust: 0.3

vendor:ciscomodel:iosscope:eqversion:11.2.10

Trust: 0.3

vendor:ciscomodel:iosscope:eqversion:11.2.8

Trust: 0.3

vendor:ciscomodel:ios 11.2pscope: - version: -

Trust: 0.3

vendor:ciscomodel:gigabit switch routerscope:eqversion:12016

Trust: 0.3

vendor:ciscomodel:gigabit switch routerscope:eqversion:12012

Trust: 0.3

vendor:ciscomodel:gigabit switch routerscope:eqversion:12008

Trust: 0.3

vendor:ciscomodel:ios 12.0 s1scope:neversion: -

Trust: 0.3

vendor:ciscomodel:ios 11.2 gs0.2scope:neversion: -

Trust: 0.3

sources: BID: 1541 // CNNVD: CNNVD-200010-085 // NVD: CVE-2000-0700

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2000-0700
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200010-085
value: MEDIUM

Trust: 0.6

VULHUB: VHN-2277
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2000-0700
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-2277
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-2277 // CNNVD: CNNVD-200010-085 // NVD: CVE-2000-0700

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2000-0700

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200010-085

TYPE

unknown

Trust: 0.6

sources: CNNVD: CNNVD-200010-085

EXTERNAL IDS

db:BIDid:1541

Trust: 2.0

db:OSVDBid:793

Trust: 1.7

db:OSVDBid:798

Trust: 1.7

db:NVDid:CVE-2000-0700

Trust: 1.7

db:CNNVDid:CNNVD-200010-085

Trust: 0.7

db:CISCOid:20000803 POSSIBLE ACCESS CONTROL BYPASS AND DENIAL OF SERVICE IN GIGABIT SWITCH ROUTERS USING GIGABIT ETHERNET OR FAST ETHERNET CARDS

Trust: 0.6

db:VULHUBid:VHN-2277

Trust: 0.1

sources: VULHUB: VHN-2277 // BID: 1541 // CNNVD: CNNVD-200010-085 // NVD: CVE-2000-0700

REFERENCES

url:http://www.securityfocus.com/bid/1541

Trust: 1.7

url:http://www.cisco.com/warp/public/707/gsraclbypassdos-pub.shtml

Trust: 1.7

url:http://www.osvdb.org/793

Trust: 1.7

url:http://www.osvdb.org/798

Trust: 1.7

url:http://www.cisco.com/univercd/cc/td/doc/pcat/12000.htm

Trust: 0.3

url:http://www.cisco.com/warp/public/707/sec_incident_response.shtml

Trust: 0.3

sources: VULHUB: VHN-2277 // BID: 1541 // CNNVD: CNNVD-200010-085 // NVD: CVE-2000-0700

CREDITS

First made public in a Cisco advisory published on August 3, 2000.

Trust: 0.3

sources: BID: 1541

SOURCES

db:VULHUBid:VHN-2277
db:BIDid:1541
db:CNNVDid:CNNVD-200010-085
db:NVDid:CVE-2000-0700

LAST UPDATE DATE

2024-08-14T14:29:39.588000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-2277date:2008-09-05T00:00:00
db:BIDid:1541date:2000-08-03T00:00:00
db:CNNVDid:CNNVD-200010-085date:2005-08-17T00:00:00
db:NVDid:CVE-2000-0700date:2008-09-05T20:21:40.360

SOURCES RELEASE DATE

db:VULHUBid:VHN-2277date:2000-10-20T00:00:00
db:BIDid:1541date:2000-08-03T00:00:00
db:CNNVDid:CNNVD-200010-085date:2000-10-20T00:00:00
db:NVDid:CVE-2000-0700date:2000-10-20T04:00:00