CVE-2011-2581
published 2011-09-14CVE-2011-2581: The ACL implementation in Cisco NX-OS 5.0(2) and 5.0(3) before 5.0(3)N2(1) on Nexus 5000 series switches, and NX-OS before 5.0(3)U1(2a) on Nexus 3000 series…
PriorityP429medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.99%
78.6th percentile
The ACL implementation in Cisco NX-OS 5.0(2) and 5.0(3) before 5.0(3)N2(1) on Nexus 5000 series switches, and NX-OS before 5.0(3)U1(2a) on Nexus 3000 series switches, does not properly handle comments in conjunction with deny statements, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by sending packets, aka Bug IDs CSCto09813 and CSCtr61490.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nexus_5000_and_3000_series_switches | — | — |
| cisco | nx-os | <= 5.0\(3\)u1\(2\) | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Nexus 5000 and 3000 Series Switches Access Control List Bypass Vulnerability
vendor_cisco
CVE-2011-2581 Cisco Nexus 5000 and 3000 Series Switches Access Control List Bypass Vulnerability
CVE-2011-2581: Cisco Nexus 5000 and 3000 Series Switches Access Control List Bypass Vulnerability
A vulnerability exists in Cisco Nexus 5000 and 3000 Series Switches that may allow traffic to bypass deny statements in access control lists (ACLs) that are configured on the device. Cisco has released software updates that address this vulnerability. A workaround is available to mitigate this vulnerability. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20110907-nexus .
Bug IDs: CSCto09813, CSCtr61490
GHSA
GHSA-c76p-58cp-48fg: The ACL implementation in Cisco NX-OS 5
ghsa_unreviewed·2022-05-13
CVE-2011-2581 [MEDIUM] GHSA-c76p-58cp-48fg: The ACL implementation in Cisco NX-OS 5
The ACL implementation in Cisco NX-OS 5.0(2) and 5.0(3) before 5.0(3)N2(1) on Nexus 5000 series switches, and NX-OS before 5.0(3)U1(2a) on Nexus 3000 series switches, does not properly handle comments in conjunction with deny statements, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by sending packets, aka Bug IDs CSCto09813 and CSCtr61490.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/45883http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9250c.shtmlhttp://www.securitytracker.com/id?1026019http://secunia.com/advisories/45883http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9250c.shtmlhttp://www.securitytracker.com/id?1026019
2011-09-14
Published