Cisco IOS XR on ASR 9000 devices does not properly use compression for port-range and address-range encoding, which allows remote attackers to bypass intended Typhoon line-card ACL restrictions via transit traffic, aka Bug ID CSCup30133.
2014-10-05T01:55:13.110
2025-04-12T10:46:40.837
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | cisco | ios_xr | * | Yes |
Hardware | cisco | asr_9000_rsp440_router | - | Yes |
Hardware | cisco | asr_9001 | - | Yes |
Hardware | cisco | asr_9006 | - | Yes |
Hardware | cisco | asr_9010 | - | Yes |
Hardware | cisco | asr_9904 | - | Yes |
Hardware | cisco | asr_9912 | - | Yes |
Hardware | cisco | asr_9922 | - | Yes |