发布时间 :1999-04-01 00:00:00
修订时间 :2008-09-09 08:34:32

[原文]In Cisco routers under some versions of IOS 12.0 running NAT, some packets may not be filtered by input access list filters.

[CNNVD]IOS Cisco路由running NAT过滤器漏洞(CNNVD-199904-005)

        运行NAT的IOS 12.0及其他一些版本下的Cisco路由输入访问列表过滤器可能不能过滤某些数据包。

- CVSS (基础分值)

CVSS分值: 5 [中等(MEDIUM)]
机密性影响: PARTIAL [很可能造成信息泄露]
完整性影响: NONE [不会对系统完整性产生影响]
可用性影响: NONE [对系统可用性无影响]
攻击复杂度: LOW [漏洞利用没有访问限制 ]
攻击向量: [--]
身份认证: NONE [漏洞利用无需身份认证]

- CPE (受影响的平台与产品)

cpe:/o:cisco:ios:12.0%281%29wCisco IOS 12.0.1 W
cpe:/o:cisco:ios:12.0%282%29xdCisco IOS 12.0.2 XD
cpe:/o:cisco:ios:12.0sCisco IOS 12.0S
cpe:/o:cisco:ios:12.0%281%29xa3Cisco IOS 12.0.1 XA3
cpe:/o:cisco:ios:12.0Cisco IOS 12.0
cpe:/o:cisco:ios:12.0%282%29xcCisco IOS 12.0.2 XC
cpe:/o:cisco:ios:12.0%281%29xeCisco IOS 12.0.1 XE
cpe:/o:cisco:ios:12.0tCisco IOS 12.0T
cpe:/o:cisco:ios:12.0%282%29xgCisco IOS 12.0.2 XG
cpe:/o:cisco:ios:12.0dbCisco IOS 12.0DB
cpe:/o:cisco:ios:12.0%282%29xfCisco IOS 12.0.2 XF
cpe:/o:cisco:ios:12.0%281%29xbCisco IOS 12.0.1 XB

- OVAL (用于检测的技术细节)

oval:org.mitre.oval:def:5574Cisco IOS Input Access List Packet Leakage Flaw

- 漏洞信息

中危 未知
1999-04-01 00:00:00 2005-05-02 00:00:00
Cisco IOS NAT ACL Bypass

IOS contains a flaw that may allow a malicious user to bypass access control lists. The issue is triggered by the manner in which packets are handled when NAT is enabled. It is possible that the flaw may allow unaunthorized traffic to enter a protected network.

1999-04-08 1999-04-08
Upgrade to version indicated by Cisco product matrix, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Unknown or Incomplete