CVE-2015-6366
published 2015-11-13CVE-2015-6366: Cisco IOS 15.2(04)M6 and 15.4(03)S lets physical-interface ACLs supersede tunnel-interface ACLs, which allows remote attackers to bypass intended…
PriorityP429medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.64%
74.0th percentile
Cisco IOS 15.2(04)M6 and 15.4(03)S lets physical-interface ACLs supersede tunnel-interface ACLs, which allows remote attackers to bypass intended network-traffic restrictions in opportunistic circumstances by using a tunnel, aka Bug ID CSCur01042.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software Tunnel Interfaces Security Bypass Vulnerability
vendor_cisco·2015-11-12·CVSS 5.0
CVE-2015-6366 [MEDIUM] CWE-20 Cisco IOS Software Tunnel Interfaces Security Bypass Vulnerability
Cisco IOS Software Tunnel Interfaces Security Bypass Vulnerability
A vulnerability in Cisco devices running IOS Software versions 15.2(04)M6 and 15.4(03)S configured with access control lists (ACLs) could allow an unauthenticated, remote user connected to a tunnel interface to bypass configured ACLs on tunnel interfaces if the ACL on the physical interface permits the traffic to pass.
The vulnerability is due to the physical interface ignoring the tunnel interface ACLs. A user could exploit this vulnerability to bypass configured tunnel interface ACLs and pass denied traffic across tunnel interfaces. If successful, the user could pass traffic as if the ACLs did not exist.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability ar
Cisco
Cisco IOS Software Tunnel Interfaces Security Bypass Vulnerability
vendor_cisco
CVE-2015-6366 Cisco IOS Software Tunnel Interfaces Security Bypass Vulnerability
CVE-2015-6366: Cisco IOS Software Tunnel Interfaces Security Bypass Vulnerability
A vulnerability in Cisco devices running IOS Software versions 15.2(04)M6 and 15.4(03)S configured with access control lists (ACLs) could allow an unauthenticated, remote user connected to a tunnel interface to bypass configured ACLs on tunnel interfaces if the ACL on the physical interface permits the traffic to pass. The vulnerability is due to the physical interface ignoring the tunnel interface ACLs. A user could exploit this vulnerability to bypass configured tunnel interface ACLs and pass denied traffic across tunnel interfaces. If successful, the user could pass traffic as if the ACLs did not exist. Cisco has released software updates that address this vulnerability.
CWE: CWE-20, CWE-20
Bug IDs: CSCur0
GHSA
GHSA-686v-2qvh-3m6r: Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2015-6366 [MEDIUM] CWE-284 GHSA-686v-2qvh-3m6r: Cisco IOS 15
Cisco IOS 15.2(04)M6 and 15.4(03)S lets physical-interface ACLs supersede tunnel-interface ACLs, which allows remote attackers to bypass intended network-traffic restrictions in opportunistic circumstances by using a tunnel, aka Bug ID CSCur01042.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-11-13
Published