CVE-2015-0610
published 2015-02-12CVE-2015-0610: Race condition in the object-group ACL feature in Cisco IOS 15.5(2)T and earlier allows remote attackers to bypass intended access restrictions via crafted…
PriorityP426medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.43%
69.8th percentile
Race condition in the object-group ACL feature in Cisco IOS 15.5(2)T and earlier allows remote attackers to bypass intended access restrictions via crafted network traffic that triggers improper handling of the timing of process switching and Cisco Express Forwarding (CEF) switching, aka Bug ID CSCun21071.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | <= 15.5\(2\)t | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software Access Control List Bypass Vulnerability
vendor_cisco·2015-02-11·CVSS 4.3
CVE-2015-0610 [MEDIUM] CWE-362 Cisco IOS Software Access Control List Bypass Vulnerability
Cisco IOS Software Access Control List Bypass Vulnerability
A vulnerability in Cisco IOS Software access control lists (ACLs) that use object groups could occasionally allow an unauthenticated, remote attacker to bypass the ACL.
The vulnerability is due to a race condition between process switching and Cisco Express Forwarding switching while evaluating ACLs with object groups. An attacker could exploit this vulnerability by sending enough traffic through an affected router to trigger the race condition.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker may need access to trusted, internal networks behind a firewall to send enough traffic to trigger a race condition on the targeted device. This access r
GHSA
GHSA-cf75-gfh6-5482: Race condition in the object-group ACL feature in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2015-0610 [MEDIUM] CWE-362 GHSA-cf75-gfh6-5482: Race condition in the object-group ACL feature in Cisco IOS 15
Race condition in the object-group ACL feature in Cisco IOS 15.5(2)T and earlier allows remote attackers to bypass intended access restrictions via crafted network traffic that triggers improper handling of the timing of process switching and Cisco Express Forwarding (CEF) switching, aka Bug ID CSCun21071.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0610http://tools.cisco.com/security/center/viewAlert.x?alertId=37423http://www.securityfocus.com/bid/72565http://www.securitytracker.com/id/1031732https://exchange.xforce.ibmcloud.com/vulnerabilities/100807http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0610http://tools.cisco.com/security/center/viewAlert.x?alertId=37423http://www.securityfocus.com/bid/72565http://www.securitytracker.com/id/1031732https://exchange.xforce.ibmcloud.com/vulnerabilities/100807
2015-02-12
Published