CVE-2001-0864
Last modified
CVE-2001-0864 is a vulnerability of currently unknown severity. Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly handle the implicit "deny ip any any" rule in an outgoing ACL when the ACL contains exactly 448 entries, which can allow some outgoing packets to bypass access restrictions.. EPSS estimates a 1.39% chance of exploitation in the next 30 days.
Description
Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly handle the implicit "deny ip any any" rule in an outgoing ACL when the ACL contains exactly 448 entries, which can allow some outgoing packets to bypass access restrictions.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | 12000 Router | All versions |
References
- http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtmlPatch, Vendor Advisory
- http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-0864?
How severe is CVE-2001-0864?
How do I fix CVE-2001-0864?
Are you affected by CVE-2001-0864?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
