ID

VAR-200010-0156


TITLE

Cisco IOS Extended Access List Failure Vulnerability

Trust: 0.3

sources: BID: 1880

DESCRIPTION

IOS is the firmware used by many Cisco network devices. In some versions of IOS 12.x (verified on 12.1(4) and reportedly other versions), certain rules in extended access control lists will not be enforced. This may allow attackers to access vulnerable network services thought to be protected by the access control lists. The reason for this behaviour is not yet known.

Trust: 0.3

sources: BID: 1880

AFFECTED PRODUCTS

vendor:ciscomodel:iosscope:eqversion:12.1(4)

Trust: 0.3

vendor:ciscomodel:iosscope:neversion:12.0.7

Trust: 0.3

vendor:ciscomodel:ios 12.1 e1scope:neversion: -

Trust: 0.3

sources: BID: 1880

TYPE

Unknown

Trust: 0.3

sources: BID: 1880

EXTERNAL IDS

db:BIDid:1880

Trust: 0.3

sources: BID: 1880

REFERENCES

url:http://www.cisco.com/warp/public/707/sec_incident_response.shtml

Trust: 0.3

sources: BID: 1880

CREDITS

First posted to Bugtraq by Mike Bressem <mb@imsc.net> on Oct 22, 2000.

Trust: 0.3

sources: BID: 1880

SOURCES

db:BIDid:1880

LAST UPDATE DATE

2022-05-17T01:42:55.189000+00:00


SOURCES UPDATE DATE

db:BIDid:1880date:2000-10-22T00:00:00

SOURCES RELEASE DATE

db:BIDid:1880date:2000-10-22T00:00:00