CVE-2001-0929
published 2001-11-28CVE-2001-0929: Cisco IOS Firewall Feature set, aka Context Based Access Control (CBAC) or Cisco Secure Integrated Software, for IOS 11.2P through 12.2T does not properly…
PriorityP431high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.09%
79.7th percentile
Cisco IOS Firewall Feature set, aka Context Based Access Control (CBAC) or Cisco Secure Integrated Software, for IOS 11.2P through 12.2T does not properly check the IP protocol type, which could allow remote attackers to bypass access control lists.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
A Vulnerability in IOS Firewall Feature Set
vendor_cisco·2001-11-29
CVE-2001-0929 CWE-287 A Vulnerability in IOS Firewall Feature Set
A Vulnerability in IOS Firewall Feature Set
The IOS Firewall Feature set, also known as Cisco Secure Integrated
Software, also known as Context Based Access Control (CBAC), and introduced in
IOS version 11.2P, has a vulnerability that permits traffic normally expected
to be denied by the dynamic access control lists.
This vulnerability is documented as Cisco Bug ID
CSCdv48261.
No other Cisco product is vulnerable.
There is no workaround.
This advisory is available at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20011128-ios-cbac-dynacl
Cisco
A Vulnerability in IOS Firewall Feature Set
vendor_cisco
CVE-2001-0929 A Vulnerability in IOS Firewall Feature Set
CVE-2001-0929: A Vulnerability in IOS Firewall Feature Set
The IOS Firewall Feature set, also known as Cisco Secure Integrated Software, also known as Context Based Access Control (CBAC), and introduced in IOS version 11.2P, has a vulnerability that permits traffic normally expected to be denied by the dynamic access control lists. This vulnerability is documented as Cisco Bug ID CSCdv48261 . No other Cisco product is vulnerable. There is no workaround. This advisory is available at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20011128-ios-cbac-dynacl
CWE: CWE-287, CWE-287
Bug IDs: CSCdv48261, CSCdv48261
GHSA
GHSA-c9cp-qwv7-4m5r: Cisco IOS Firewall Feature set, aka Context Based Access Control (CBAC) or Cisco Secure Integrated Software, for IOS 11
ghsa_unreviewed·2022-04-30
CVE-2001-0929 [HIGH] GHSA-c9cp-qwv7-4m5r: Cisco IOS Firewall Feature set, aka Context Based Access Control (CBAC) or Cisco Secure Integrated Software, for IOS 11
Cisco IOS Firewall Feature set, aka Context Based Access Control (CBAC) or Cisco Secure Integrated Software, for IOS 11.2P through 12.2T does not properly check the IP protocol type, which could allow remote attackers to bypass access control lists.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.cisco.com/warp/public/707/IOS-cbac-dynacl-pub.shtmlhttp://www.kb.cert.org/vuls/id/362483http://www.osvdb.org/808http://www.securityfocus.com/bid/3588https://exchange.xforce.ibmcloud.com/vulnerabilities/7614http://www.cisco.com/warp/public/707/IOS-cbac-dynacl-pub.shtmlhttp://www.kb.cert.org/vuls/id/362483http://www.osvdb.org/808http://www.securityfocus.com/bid/3588https://exchange.xforce.ibmcloud.com/vulnerabilities/7614
2001-11-28
Published