ID

VAR-200112-0063


CVE

CVE-2001-0862


TITLE

Cisco Access Control List Fragment Non-blocking Vulnerability

Trust: 0.9

sources: BID: 3535 // CNNVD: CNNVD-200112-017

DESCRIPTION

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not block non-initial packet fragments, which allows remote attackers to bypass the ACL. Cisco IOS is the router firmware included with numerous devices manufactured by Cisco Systems. Non-initial fragmented packets sent to a protected host will bypass the ACL. This could allow a user to communicate with 'protected' hosts, bypassing security policy. A remote attacker bypasses the ACL

Trust: 1.26

sources: NVD: CVE-2001-0862 // BID: 3535 // VULHUB: VHN-3669

AFFECTED PRODUCTS

vendor:ciscomodel:12000 routerscope:eqversion:*

Trust: 1.0

vendor:ciscomodel:12000 routerscope: - version: -

Trust: 0.6

vendor:ciscomodel:ios 12.0stscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 12.0sscope: - version: -

Trust: 0.3

sources: BID: 3535 // CNNVD: CNNVD-200112-017 // NVD: CVE-2001-0862

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2001-0862
value: HIGH

Trust: 1.0

CNNVD: CNNVD-200112-017
value: HIGH

Trust: 0.6

VULHUB: VHN-3669
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2001-0862
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-3669
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-3669 // CNNVD: CNNVD-200112-017 // NVD: CVE-2001-0862

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2001-0862

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200112-017

TYPE

Design Error

Trust: 0.9

sources: BID: 3535 // CNNVD: CNNVD-200112-017

EXTERNAL IDS

db:BIDid:3535

Trust: 2.0

db:NVDid:CVE-2001-0862

Trust: 1.7

db:OSVDBid:1985

Trust: 1.7

db:CNNVDid:CNNVD-200112-017

Trust: 0.7

db:CISCOid:20011114 MULTIPLE VULNERABILITIES IN ACCESS CONTROL LIST IMPLEMENTATION FOR CISCO 12000 SERIES INTERNET ROUTER

Trust: 0.6

db:CIACid:M-018

Trust: 0.6

db:XFid:7550

Trust: 0.6

db:VULHUBid:VHN-3669

Trust: 0.1

sources: VULHUB: VHN-3669 // BID: 3535 // CNNVD: CNNVD-200112-017 // NVD: CVE-2001-0862

REFERENCES

url:http://www.securityfocus.com/bid/3535

Trust: 1.7

url:http://www.ciac.org/ciac/bulletins/m-018.shtml

Trust: 1.7

url:http://www.cisco.com/warp/public/707/gsr-acl-pub.shtml

Trust: 1.7

url:http://www.osvdb.org/1985

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/7550

Trust: 1.1

url:http://xforce.iss.net/static/7550.php

Trust: 0.6

url:http://www.cisco.com/warp/public/707/sec_incident_response.shtml

Trust: 0.3

sources: VULHUB: VHN-3669 // BID: 3535 // CNNVD: CNNVD-200112-017 // NVD: CVE-2001-0862

CREDITS

This vulnerability was announced in a Cisco Security Advisory on November 14, 2001.

Trust: 0.9

sources: BID: 3535 // CNNVD: CNNVD-200112-017

SOURCES

db:VULHUBid:VHN-3669
db:BIDid:3535
db:CNNVDid:CNNVD-200112-017
db:NVDid:CVE-2001-0862

LAST UPDATE DATE

2025-04-03T22:16:57.224000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-3669date:2017-10-10T00:00:00
db:BIDid:3535date:2001-11-14T00:00:00
db:CNNVDid:CNNVD-200112-017date:2005-05-02T00:00:00
db:NVDid:CVE-2001-0862date:2025-04-03T01:03:51.193

SOURCES RELEASE DATE

db:VULHUBid:VHN-3669date:2001-12-06T00:00:00
db:BIDid:3535date:2001-11-14T00:00:00
db:CNNVDid:CNNVD-200112-017date:2001-12-06T00:00:00
db:NVDid:CVE-2001-0862date:2001-12-06T05:00:00