CVE-2007-5134
published 2007-09-27CVE-2007-5134: Cisco Catalyst 6500 and Cisco 7600 series devices use 127/8 IP addresses for Ethernet Out-of-Band Channel (EOBC) internal communication, which might allow…
PriorityP426medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.48%
82.8th percentile
Cisco Catalyst 6500 and Cisco 7600 series devices use 127/8 IP addresses for Ethernet Out-of-Band Channel (EOBC) internal communication, which might allow remote attackers to send packets to an interface for which network exposure was unintended.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catalyst_6500_ws-svc-nam-1 | — | — |
| cisco | catalyst_6500_ws-svc-nam-1 | — | — |
| cisco | catalyst_6500_ws-svc-nam-2 | — | — |
| cisco | catalyst_6500_ws-svc-nam-2 | — | — |
| cisco | catalyst_6500_ws-x6380-nam | — | — |
| cisco | catalyst_6500_ws-x6380-nam | — | — |
| cisco | catalyst_7600_ws-svc-nam-1 | — | — |
| cisco | catalyst_7600_ws-svc-nam-1 | — | — |
| cisco | catalyst_7600_ws-svc-nam-2 | — | — |
| cisco | catalyst_7600_ws-svc-nam-2 | — | — |
| cisco | catalyst_7600_ws-x6380-nam | — | — |
| cisco | catalyst_7600_ws-x6380-nam | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
| cisco | catos | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS on Catalyst 6500 and Cisco 7600 Access Control List Bypass Vulnerability
vendor_cisco·2007-09-26·CVSS 5.0
CVE-2007-5134 [MEDIUM] Cisco IOS on Catalyst 6500 and Cisco 7600 Access Control List Bypass Vulnerability
Cisco IOS on Catalyst 6500 and Cisco 7600 Access Control List Bypass Vulnerability
Cisco IOS running on Catalyst 6500 and Cisco 7600 contains a vulnerability that could allow an unauthenticated, remote attacker to bypass configured ACLs.
The vulnerability exists because the affected devices accept traffic to IP addresses that are reserved for use by the Ethernet Out-of-Band Channel (EOBC). These addresses are not typically protected by ACLs, as they are not expected to be reachable outside the EOBC. An unauthenticated, remote attacker could exploit this vulnerability to bypass ACLs configured to protect exposed management addresses and send packets to intelligent modules such as the Supervisor or Multi-layer Switch Feature Card (MSFC).
Exploit code is not required to exploit this vulnerab
GHSA
GHSA-2j9f-fxq3-5v7w: Cisco Catalyst 6500 and Cisco 7600 series devices use 127/8 IP addresses for Ethernet Out-of-Band Channel (EOBC) internal communication, which might a
ghsa_unreviewed·2022-05-01
CVE-2007-5134 [MEDIUM] GHSA-2j9f-fxq3-5v7w: Cisco Catalyst 6500 and Cisco 7600 series devices use 127/8 IP addresses for Ethernet Out-of-Band Channel (EOBC) internal communication, which might a
Cisco Catalyst 6500 and Cisco 7600 series devices use 127/8 IP addresses for Ethernet Out-of-Band Channel (EOBC) internal communication, which might allow remote attackers to send packets to an interface for which network exposure was unintended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://seclists.org/fulldisclosure/2007/Sep/0573.htmlhttp://secunia.com/advisories/26988http://securitytracker.com/id?1018742http://www.cisco.com/warp/public/707/cisco-sr-20070926-lb.shtmlhttp://www.securityfocus.com/bid/25822http://www.securitytracker.com/id?1018743http://www.vupen.com/english/advisories/2007/3276https://exchange.xforce.ibmcloud.com/vulnerabilities/36826http://seclists.org/fulldisclosure/2007/Sep/0573.htmlhttp://secunia.com/advisories/26988http://securitytracker.com/id?1018742http://www.cisco.com/warp/public/707/cisco-sr-20070926-lb.shtmlhttp://www.securityfocus.com/bid/25822http://www.securitytracker.com/id?1018743http://www.vupen.com/english/advisories/2007/3276https://exchange.xforce.ibmcloud.com/vulnerabilities/36826
2007-09-27
Published