PT-2001-2030 · Cisco · Cisco 12000+1
Published
2001-12-06
·
Updated
2017-10-10
·
CVE-2001-0864
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco 12000 with IOS version 12.0
Description
The issue arises from the improper handling of the implicit "deny ip any any" rule in an outgoing ACL when it contains exactly 448 entries. This can lead to some outgoing packets bypassing access restrictions.
Recommendations
For Cisco 12000 with IOS version 12.0, consider reconfiguring the ACL to avoid having exactly 448 entries as a temporary workaround to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco 12000
Ios