CVE-2015-6365
published 2015-11-14CVE-2015-6365: Cisco IOS 15.2(04)M and 15.4(03)M lets physical-interface ACLs supersede virtual PPP interface ACLs, which allows remote authenticated users to bypass intended…
PriorityP420medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
1.37%
68.7th percentile
Cisco IOS 15.2(04)M and 15.4(03)M lets physical-interface ACLs supersede virtual PPP interface ACLs, which allows remote authenticated users to bypass intended network-traffic restrictions in opportunistic circumstances by using PPP, aka Bug ID CSCur61303.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xrxc-57v3-82rr: Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2015-6365 [MEDIUM] CWE-20 GHSA-xrxc-57v3-82rr: Cisco IOS 15
Cisco IOS 15.2(04)M and 15.4(03)M lets physical-interface ACLs supersede virtual PPP interface ACLs, which allows remote authenticated users to bypass intended network-traffic restrictions in opportunistic circumstances by using PPP, aka Bug ID CSCur61303.
Cisco
Cisco IOS Software Virtual PPP Interfaces Security Bypass Vulnerability
vendor_cisco·2015-11-13·CVSS 4.0
CVE-2015-6365 [MEDIUM] CWE-20 Cisco IOS Software Virtual PPP Interfaces Security Bypass Vulnerability
Cisco IOS Software Virtual PPP Interfaces Security Bypass Vulnerability
A vulnerability in Cisco devices that are running Cisco IOS Software Release 15.2(04)M or Cisco IOS Software Release 15.4(03)M and are configured to use access control lists (ACLs) could allow a user who is connected to an authenticated PPP session to bypass ACLs that are configured on virtual PPP interfaces, if the ACL on the physical interface permits the traffic to pass.
The vulnerability is due to the physical interface ignoring virtual PPP ACLs. An attacker could exploit this vulnerability to bypass virtual PPP ACLs and pass denied traffic across virtual PPP interfaces. A successful exploit could allow the attacker to pass traffic as if the ACLs do not exist.
Cisco has released software updates that address thi
Cisco
Cisco IOS Software Virtual PPP Interfaces Security Bypass Vulnerability
vendor_cisco
CVE-2015-6365 Cisco IOS Software Virtual PPP Interfaces Security Bypass Vulnerability
CVE-2015-6365: Cisco IOS Software Virtual PPP Interfaces Security Bypass Vulnerability
A vulnerability in Cisco devices that are running Cisco IOS Software Release 15.2(04)M or Cisco IOS Software Release 15.4(03)M and are configured to use access control lists (ACLs) could allow a user who is connected to an authenticated PPP session to bypass ACLs that are configured on virtual PPP interfaces, if the ACL on the physical interface permits the traffic to pass. The vulnerability is due to the physical interface ignoring virtual PPP ACLs. An attacker could exploit this vulnerability to bypass virtual PPP ACLs and pass denied traffic across virtual PPP interfaces. A successful exploit could allow the attacker to pass traffic as if the ACLs do not exist. Cisco has released software updates that
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-11-14
Published