CVE-2015-0694
published 2015-04-11CVE-2015-0694: Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a single-host constraint, which allows remote attackers to…
PriorityP431medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.63%
73.8th percentile
Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a single-host constraint, which allows remote attackers to bypass intended network-resource access restrictions by using an address that was not supposed to have been allowed, aka Bug ID CSCur28806.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qpjg-v5w5-9439: Cisco ASR 9000 devices with software 5
ghsa_unreviewed·2022-05-17
CVE-2015-0694 [MEDIUM] CWE-284 GHSA-qpjg-v5w5-9439: Cisco ASR 9000 devices with software 5
Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a single-host constraint, which allows remote attackers to bypass intended network-resource access restrictions by using an address that was not supposed to have been allowed, aka Bug ID CSCur28806.
Cisco
Cisco Aggregate Services Router 9000 ASR9K Security Bypass Vulnerability
vendor_cisco·2015-04-09·CVSS 5.0
CVE-2015-0694 [MEDIUM] CWE-264 Cisco Aggregate Services Router 9000 ASR9K Security Bypass Vulnerability
Cisco Aggregate Services Router 9000 ASR9K Security Bypass Vulnerability
A vulnerability in the Object-ACL matching process of Cisco Aggregation Services Router 9000 (ASR9K) could allow an unauthenticated, remote attacker to bypass the protection offered by a configured access control list (ACL) on an affected device.
The vulnerability is due to ASR9K incorrectly handling host access control entries by incorrectly matching any address instead of the specified host address. An attacker could exploit this vulnerability to bypass the access control list leading to traffic loss or unwanted permits.
Cisco has confirmed the vulnerability and released software updates.
The impact of an exploit depends on ACLs in use on the affected system. Attackers who could bypass the configured ACLs could
No detection rules found.
No public exploits indexed.
2015-04-11
Published