Skip to main content

Cisco IOS Software Tunnel Interfaces Security Bypass Vulnerability

Last Update Date: 17 Nov 2015 Release Date: 16 Nov 2015 4052 Views

RISK: High Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability was identified in Cisco IOS. A remote user can bypass access controls on the target system.

 
A remote user connected to a tunnel interface can bypass the access control lists (ACLs) when the physical interface ACLs permit the traffic to pass.

Impact

  • Security Restriction Bypass

System / Technologies affected

  • Cisco IOS Software versions 15.2(04)M6 and 15.4(03)S

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix.

Vulnerability Identifier


Source


Related Link