Cisco Security Advisory
Cisco IOS on Catalyst 6500 and Cisco 7600 Access Control List Bypass Vulnerability
Click Icon to Copy Verbose Score
AV:N/AC:L/Au:N/C:P/I:N/A:N/E:F/RL:OF/RC:C
-
Cisco IOS running on Catalyst 6500 and Cisco 7600 contains a vulnerability that could allow an unauthenticated, remote attacker to bypass configured ACLs.
The vulnerability exists because the affected devices accept traffic to IP addresses that are reserved for use by the Ethernet Out-of-Band Channel (EOBC). These addresses are not typically protected by ACLs, as they are not expected to be reachable outside the EOBC. An unauthenticated, remote attacker could exploit this vulnerability to bypass ACLs configured to protect exposed management addresses and send packets to intelligent modules such as the Supervisor or Multi-layer Switch Feature Card (MSFC).
Exploit code is not required to exploit this vulnerability.
Cisco has confirmed this vulnerability in a security response and released updated software.
The vulnerability affects Catalyst 6500 and Cisco 7000 devices that are running in both Hybrid Mode (CatOS on the Supervisor Engine and IOS on the MSFC) and Native Mode (IOS on both the Supervisor Engine and the MSFC). The 127.0.0.0/8 network is reserved for loopback and internal communications, as specified in RFC 3330. As such, traffic bound for this network is not routed over the public Internet. However, some default configurations of IOS running on Cisco Routers may allow such traffic to pass over trusted internal networks. The circumstances that would allow this are very specific and are unlikely to occur in most networks. These factors dramatically lower the pool of potential attackers. Any attacker that bypasses ACLs using this vulnerability to access an affected device must still authenticate to perform actions such as modifying configuration files.
Multiple methods exist to effectively mitigate this vulnerability without downtime or software upgrades. Administrators of high availability environments are advised to utilize ACLs or Control Plane Policing (CoPP) to prevent unwanted traffic from reaching intelligent management cards. Administrators are still encouraged to update the software running on these devices during the next scheduled and planned outage.
This vulnerability has been resolved with the release of 12.2(33)SXH.
-
Cisco has re-released a security response to address Cisco Bug ID CSCek49649 at the following link: Cisco-sr-20070926-lb
Vulnerable Products
Systems running one or more of the following versions of Cisco IOS on Cisco Catalyst 6500 and Cisco 7600 devices are vulnerable:
12.2(18r)SX
12.2(99)SX
12.2(18)ZU
12.2(18)ZY
12.2(18)IXA
12.2(18)IXB
12.2(18)IXC
12.2(18)IXD
12.2(18)SXD
12.2(18)SXE
12.2(18)SXF
12.3(18r)S
12.3(18r)SXProducts Confirmed Not Vulnerable
No other Cisco products are currently known to be affected by these vulnerabilities.
-
Administrators are advised to implement ACLs as specified within the Cisco Security Response to restrict access to affected devices.
Administrators are advised to utilize CoPP to restrict management traffic to only authorized paths and workstations.
Administrators may consider placing blackhole routes on edge devices to ensure that malicious traffic cannot enter the network.
The Cisco Applied Intelligence team has created the following companion document to guide administrators in identifying and mitigating attempts to exploit this vulnerability prior to applying updated software: cisco-air-20070926-lb
-
Cisco customers with active contracts can obtain updates through the Software Center at the following link: Cisco. Cisco customers without contracts can obtain upgrades by contacting the Cisco Technical Assistance Center at 1-800-553-2447 or 1-408-526-7209 or via e-mail at tac@cisco.com.
-
The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.
-
To learn about Cisco security vulnerability disclosure policies and publications, see the Security Vulnerability Policy. This document also contains instructions for obtaining fixed software and receiving security vulnerability information from Cisco.
-
Show LessVersion Description Section Status Date 1.0 Initial Release NA Final 2007-Sep-26
-
THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.
A stand-alone copy or paraphrase of the text of this document that omits the distribution URL is an uncontrolled copy, and may lack important information or contain factual errors. The information in this document is intended for end-users of Cisco products.