Cisco Context Based Access Control协议检查绕过漏洞

漏洞信息详情

Cisco Context Based Access Control协议检查绕过漏洞

漏洞简介

用于IOS 11.2P至12.2T的Cisco IOS 防火墙特征设置,也称为Context Based Access Control (CBAC)或Cisco Secure Integrated软件不能正确检查IP协议类型。远程攻击者可以利用该漏洞绕过访问控制列表。

漏洞公告

Cisco has released an advisory, along with fixes to address this issue.
Cisco IOS 12.2T

  • Cisco IOS 12.2(7)

Cisco IOS 11.2 P

  • Cisco IOS 12.0(21)

Cisco IOS 11.3 T

  • Cisco IOS 12.0(21)

Cisco IOS 12.0 XA

  • Cisco IOS 12.1(12)

Cisco IOS 12.0 XI

  • Cisco IOS 12.1(12)

Cisco IOS 12.0 XM

  • Cisco IOS 12.1(12)

Cisco IOS 12.0 XC

  • Cisco IOS 12.1(12)

Cisco IOS 12.0 XB

  • Cisco IOS 12.1(12)

Cisco IOS 12.0 T

  • Cisco IOS 12.1(12)

Cisco IOS 12.0 XG

  • Cisco IOS 12.1(12)

Cisco IOS 12.0 XQ

  • Cisco IOS 12.1(12)

Cisco IOS 12.0 XV

  • Cisco IOS 12.1(12)

Cisco IOS 12.0 XK

  • Cisco IOS 12.1(12)

Cisco IOS 12.0 XR

  • Cisco IOS 12.1(12)

Cisco IOS 12.0 XE

  • Cisco IOS 12.1(12)

Cisco IOS 12.0 XD

  • Cisco IOS 12.1(12)

Cisco IOS 12.1 YC

  • Cisco IOS 12.1(5)YC2

Cisco IOS 12.1 E

  • Cisco IOS 12.1(10)E

Cisco IOS 12.1 XI

  • Cisco IOS 12.2(6)

Cisco IOS 12.1 T

  • Cisco IOS 12.2(6)

Cisco IOS 12.1 XK

  • Cisco IOS 12.2(6)

Cisco IOS 12.1 YB

  • Cisco IOS 12.1(5)YB5

Cisco IOS 12.1 XG

  • Cisco IOS 12.1(3)XG6

Cisco IOS 12.1 XB

  • Cisco IOS 12.1(5)YB1

Cisco IOS 12.1

  • Cisco IOS 12.1(12)

Cisco IOS 12.1 XM

  • Cisco IOS 12.1(5)XM6

Cisco IOS 12.1 YF

  • Cisco IOS 12.1(5)YF3

Cisco IOS 12.1 XL

  • Cisco IOS 12.2(6)

Cisco IOS 12.1 XF

  • Cisco IOS 12.1(2)XF5

Cisco IOS 12.1 YE

  • Cisco IOS 12.1(5)YE4

Cisco IOS 12.1 XH

  • Cisco IOS 12.2(6)

Cisco IOS 12.2 XJ

  • Cisco IOS 12.2(2)XJ1

Cisco IOS 12.2 DD

  • Cisco IOS 12.2(4)B

Cisco IOS 12.2 XE

  • Cisco IOS 12.2(1)XE2

Cisco IOS 12.2 XD

  • Cisco IOS 12.2(2)XD3

Cisco IOS 12.2 XK

  • Cisco IOS 12.2(2)XK5

Cisco IOS 12.2 XQ

  • Cisco IOS 12.2(2)XQ2

Cisco IOS 12.2 XI

  • Cisco IOS 12.2(2)XI1

Cisco IOS 12.2

  • Cisco IOS 12.2(6)

Cisco IOS 12.2 XH

  • Cisco IOS 12.2(2)XH2

参考网址

来源:US-CERT Vulnerability Note: VU#362483
名称: VU#362483
链接:http://www.kb.cert.org/vuls/id/362483

来源: CISCO
名称: 20011128 A Vulnerability in IOS Firewall Feature Set
链接:http://www.cisco.com/warp/public/707/IOS-cbac-dynacl-pub.shtml

来源: XF
名称: ios-cbac-bypass-acl(7614)
链接:http://xforce.iss.net/xforce/xfdb/7614

来源: BID
名称: 3588
链接:http://www.securityfocus.com/bid/3588

来源: OSVDB
名称: 808
链接:http://www.osvdb.org/808

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享