CVE-2015-0610

Cisco IOS < 15.5(2)T - Race Condition in Object-Group ACL Feature

Title source: llm
STIX 2.1

Description

Race condition in the object-group ACL feature in Cisco IOS 15.5(2)T and earlier allows remote attackers to bypass intended access restrictions via crafted network traffic that triggers improper handling of the timing of process switching and Cisco Express Forwarding (CEF) switching, aka Bug ID CSCun21071.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031732
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/100807
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72565

Scores

EPSS 0.0143
EPSS Percentile 69.6%

Details

CWE
CWE-362
Status published
Products (4)
cisco/ios 15.5\(1\)t
cisco/ios 15.5\(1\)t1
cisco/ios 15.5t
cisco/ios < 15.5\(2\)t
Published Feb 12, 2015
Tracked Since Feb 18, 2026