Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a single-host constraint, which allows remote attackers to bypass intended network-resource access restrictions by using an address that was not supposed to have been allowed, aka Bug ID CSCur28806.
2015-04-11T01:59:03.803
2025-04-12T10:46:40.837
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | cisco | ios_xr | 5.3.0_base | Yes |
Hardware | cisco | asr_9001 | - | Yes |
Hardware | cisco | asr_9006 | - | Yes |
Hardware | cisco | asr_9010 | - | Yes |
Hardware | cisco | asr_9904 | - | Yes |
Hardware | cisco | asr_9912 | - | Yes |
Hardware | cisco | asr_9922 | - | Yes |