Описание
Cisco IOS 9.1 and earlier does not properly handle extended IP access lists when the IP route cache is enabled and the "established" keyword is set, which could allow attackers to bypass filters.
Ссылки
- PatchThird Party AdvisoryUS Government Resource
- PatchThird Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 9.1 (включая)
cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:*
EPSS
Процентиль: 55%
0.00332
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
около 3 лет назад
Cisco IOS 9.1 and earlier does not properly handle extended IP access lists when the IP route cache is enabled and the "established" keyword is set, which could allow attackers to bypass filters.
EPSS
Процентиль: 55%
0.00332
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other