MEDIUM · 5.0

CVE-2015-0694

Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a single-host constraint, which allows remote attackers to bypass intended network-resource access restri...

Vulnerability Description

Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a single-host constraint, which allows remote attackers to bypass intended network-resource access restrictions by using an address that was not supposed to have been allowed, aka Bug ID CSCur28806.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
CiscoIos Xr5.3.0_base
CiscoAsr 9001-
CiscoAsr 9006-
CiscoAsr 9010-
CiscoAsr 9904-
CiscoAsr 9912-
CiscoAsr 9922-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-0694?

CVE-2015-0694 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a single-host constraint, which allows remote attackers to bypass intended network-resource access restri...

How severe is CVE-2015-0694?

CVE-2015-0694 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-0694?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios Xr, Cisco Asr 9001, Cisco Asr 9006, Cisco Asr 9010, Cisco Asr 9904.