Executive brief
Cisco routers running older software versions contain a flaw that allows network traffic to bypass intended security restrictions. By using a technique called IP source routing, an attacker can force data packets to follow a specific path through the network, even if the administrator has explicitly tried to disable this feature. This could allow unauthorized access to internal network resources or sensitive data.
Technical details
A vulnerability exists in Cisco IOS 9.17 and earlier where the 'no ip source-route' command fails to properly drop all types of IP source routed packets. This flaw allows a remote, unauthenticated attacker to bypass security filters or access control lists (ACLs) by specifying a manual path for packets to take through the network. By exploiting this, an attacker can reach internal hosts that would otherwise be protected by the router's security policies. The issue is resolved in later versions of Cisco software where source routing is correctly disabled when configured.
Affected products
- Cisco IOS 9.17 and earlier
Timeline
- 1993-04-22: disclosed: Initial publication of the vulnerability