CVE-2001-0867

Cisco 12000 Router with IOS 12.0 and Engine 2 Line Cards - Access Control Bypass via Packet Fragment Filtering

Title source: llm
STIX 2.1

Description

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly filter does not properly filter packet fragments even when the "fragment" keyword is used in an ACL, which allows remote attackers to bypass the intended access controls.

References (5)

Core 5
Core References
Third Party Advisory, US Government Resource third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/m-018.shtml
Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtml
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3538
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/1989
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/7555

Scores

EPSS 0.0171
EPSS Percentile 75.0%

Details

Status published
Products (1)
cisco/12000_router
Published Dec 06, 2001
Tracked Since Feb 18, 2026