Vulnerability Name:

CVE-2001-0867 (CCN-7555)

Assigned:2001-11-14
Published:2001-11-14
Updated:2017-10-10
Summary:Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly filter does not properly filter packet fragments even when the "fragment" keyword is used in an ACL, which allows remote attackers to bypass the intended access controls.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2001-0867

Source: CCN
Type: CIAC Information Bulletin M-018
Cisco - Multiple Vulnerabilities in ACL Implementations

Source: CIAC
Type: UNKNOWN
M-018

Source: CCN
Type: Cisco Systems Inc. Security Advisory, 2001 November 14
Multiple Vulnerabilities in Access Control List Implementation for Cisco 12000 Series Internet Router

Source: CISCO
Type: UNKNOWN
20011114 Multiple Vulnerabilities in Access Control List Implementation for Cisco 12000 Series Internet Router

Source: OSVDB
Type: UNKNOWN
1989

Source: CCN
Type: OSVDB ID: 1989
Cisco 12000 Series Router Fragment Keyword ACL Bypass

Source: BID
Type: UNKNOWN
3538

Source: CCN
Type: BID-3538
Cisco 12000 Outgoing ACL Fragmented Packet Vulnerability

Source: CCN
Type: BID-3542
Cisco Access Control List Fragment Keyword Ignored Vulnerability

Source: XF
Type: UNKNOWN
cisco-acl-fragment-bypass(7555)

Source: XF
Type: UNKNOWN
cisco-acl-fragment-bypass(7555)

Vulnerable Configuration:Configuration 1:
  • cpe:/h:cisco:12000_router:*:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/h:cisco:12000_router:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:5754
    V
    Cisco IOS 12.0 Security Policy Circumvention Vulnerability
    2008-09-08
    BACK
    cisco 12000 router *
    cisco 12000 router *