积极预防 及时发现
快速响应 力保恢复
使用基于Engine2的IOS 12.0和line cards的Cisco 12000在ACL正好包...
发布时间:2001-12-06 信息来源:管理员

CNCVE编号:CNCVE-20010864 CVE编号:CAN-2001-0864 安全级别:中 漏洞中文描述: 使用基于Engine2的IOS 12.0和line cards的Cisco 12000在ACL正好包含448个实体的时候不能在一个正在发送的ACL中正确地处理暗含的“dent ip any any”规则,这允许一些发送包绕过访问限制。 漏洞英文描述: Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly handle the implicit "deny ip any any" rule in an outgoing ACL when the ACL contains exactly 448 entries, which can allow some outgoing packets to bypass access restrictions. 漏洞参考: Reference: CISCO:20011114 Multiple Vulnerabilities in Access Control List Implementation for Cisco 12000 Series Internet Router Reference: URL:http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtml 系统类型: 其他 漏洞类型:设计错误