Executive brief
A vulnerability in older Cisco routers could allow an attacker to bypass security rules designed to block unauthorized network traffic. This occurs when specific filtering rules are combined with performance-enhancing features, potentially allowing unauthorized access to internal systems or sensitive data. An exploit could lead to a breach of the network perimeter, compromising the confidentiality and integrity of the protected environment.
Technical details
A vulnerability exists in Cisco IOS versions 8.2 through 9.1 involving the interaction between extended IP Access Control Lists (ACLs) and the IP route cache. When an ACL uses the 'established' keyword—intended to permit only returning TCP traffic—and is applied to an interface where IP route caching is enabled, the router may fail to properly validate subsequent packets against the ACL. A remote, unauthenticated attacker can exploit this to bypass intended network restrictions and reach internal hosts. This issue is specific to certain interface configurations and requires the combination of route caching and the 'established' TCP flag check. Patch information is referenced in historical vendor advisories.
Affected products
- Cisco IOS 8.2 through 9.1
Timeline
- 1992-12-10: disclosed: Initial publication date
- 1992-12-10: advisory: NVD published date