Junglewise Threat Intelligence

CVE-1999-1306: Cisco IOS filter bypass in extended IP access lists

CVE-1999-1306 · Severity: high · CVSS 7.5 · Published 1992-12-10

Technologies: Cisco IOS. Vendors: Cisco.

Executive brief

Cisco IOS software, which runs on networking hardware like routers, contains a flaw in how it manages network traffic filters. An attacker could bypass security rules intended to block unauthorized access to the internal network. This could lead to unauthorized data access or further attacks on systems that were supposed to be protected by the router's firewall-like features.

Technical details

A vulnerability exists in Cisco IOS 9.1 and earlier involving the interaction between extended IP access control lists (ACLs) and the IP route cache. When the 'established' keyword is used in an ACL to permit return TCP traffic, and IP route caching is enabled, the router may fail to correctly apply filtering logic to subsequent packets in a flow. A remote, unauthenticated attacker can exploit this to bypass intended network access restrictions. This allows unauthorized traffic to reach protected network segments. The issue is resolved by upgrading to a non-vulnerable version of IOS or disabling the IP route cache as a workaround.

Affected products

  • Cisco IOS 9.1 and earlier

Timeline

  • 1992-12-10: disclosed
  • 1992-12-10: advisory: CERT advisory CA-1992-20 published

References

Related threats