ID

VAR-E-200709-0584


CVE

cve_id:CVE-2007-5134

Trust: 0.3

sources: BID: 25822

TITLE

Cisco Catalyst 6500 and Cisco 7600 Loopback Access Control Bypass Vulnerability

Trust: 0.3

sources: BID: 25822

DESCRIPTION

Cisco Catalyst 6500 and Cisco 7600 devices are prone to a vulnerability that may allow attackers to bypass access control lists (ACL).
Attackers may leverage this issue to access a device from an unauthorized remote location; this may aid in further attacks.

Trust: 0.3

sources: BID: 25822

AFFECTED PRODUCTS

vendor:ciscomodel:catalyst ws-x6380-namscope:eqversion:76003.1

Trust: 0.3

vendor:ciscomodel:catalyst ws-svc-nam-2scope:eqversion:76003.1

Trust: 0.3

vendor:ciscomodel:catalyst ws-svc-nam-1scope:eqversion:76003.1

Trust: 0.3

vendor:ciscomodel:catalyst ws-svc-nam-2scope:eqversion:76002.2

Trust: 0.3

vendor:ciscomodel:catalyst ws-svc-nam-1scope:eqversion:76002.2

Trust: 0.3

vendor:ciscomodel:catalyst ws-x6380-namscope:eqversion:76002.1

Trust: 0.3

vendor:ciscomodel:catalyst sup720/msfc3scope:eqversion:7600

Trust: 0.3

vendor:ciscomodel:catalyst sup2/msfc2scope:eqversion:7600

Trust: 0.3

vendor:ciscomodel:catalystscope:eqversion:65007.6(1)

Trust: 0.3

vendor:ciscomodel:catalystscope:eqversion:65007.5(1)

Trust: 0.3

vendor:ciscomodel:catalystscope:eqversion:65005.4.1

Trust: 0.3

vendor:ciscomodel:catalyst ws-x6380-namscope:eqversion:65003.1

Trust: 0.3

vendor:ciscomodel:catalyst ws-svc-nam-2scope:eqversion:65003.1

Trust: 0.3

vendor:ciscomodel:catalyst ws-svc-nam-1scope:eqversion:65003.1

Trust: 0.3

vendor:ciscomodel:catalyst ws-svc-nam-2scope:eqversion:65002.2

Trust: 0.3

vendor:ciscomodel:catalyst ws-svc-nam-1scope:eqversion:65002.2

Trust: 0.3

vendor:ciscomodel:catalyst ws-x6380-namscope:eqversion:65002.1

Trust: 0.3

vendor:ciscomodel:catalystscope:eqversion:6500

Trust: 0.3

vendor:ciscomodel:catalystscope:eqversion:7600

Trust: 0.3

sources: BID: 25822

EXPLOIT

To exploit this issue, attackers may use readily available network utilities.

Trust: 0.3

sources: BID: 25822

PRICE

Free

Trust: 0.3

sources: BID: 25822

TYPE

Access Validation Error

Trust: 0.3

sources: BID: 25822

CREDITS

The vendor credits Lee E. Rian with the discovery of this vulnerability.

Trust: 0.3

sources: BID: 25822

EXTERNAL IDS

db:NVDid:CVE-2007-5134

Trust: 0.3

db:BIDid:25822

Trust: 0.3

sources: BID: 25822

REFERENCES

url:http://www.cisco.com/warp/public/707/cisco-sr-20070926-lb.shtml

Trust: 0.3

url:http://www.cisco.com/en/us/products/hw/switches/index.html

Trust: 0.3

sources: BID: 25822

SOURCES

db:BIDid:25822

LAST UPDATE DATE

2022-07-27T09:34:02.884000+00:00


SOURCES UPDATE DATE

db:BIDid:25822date:2015-05-07T17:35:00

SOURCES RELEASE DATE

db:BIDid:25822date:2007-09-26T00:00:00