CVE-1999-1466

Cisco IOS 8.2-9.1 - Unauthenticated Access Control Bypass via Established Keyword

Title source: llm
STIX 2.1

Description

Vulnerability in Cisco routers versions 8.2 through 9.1 allows remote attackers to bypass access control lists when extended IP access lists are used on certain interfaces, the IP route cache is enabled, and the access list uses the "established" keyword.

References (2)

Core 2
Core References
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.cert.org/advisories/CA-1992-20.html
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/53

Scores

EPSS 0.0232
EPSS Percentile 81.7%

Details

Status published
Products (4)
cisco/ios 8.2
cisco/ios 8.3
cisco/ios 9.0
cisco/ios 9.1
Published Dec 10, 1992
Tracked Since Feb 18, 2026