Cisco Adaptive Security Appliance Software and Firewall Services Module Software Time-Range Object Access List Bypass Vulnerability

Related Vulnerabilities: CVE-2013-1195  

A vulnerability in the implementation of the time-range object could allow an unauthenticated, remote attacker to bypass access lists that are using the time-range option. The vulnerability is due to improper implementation of the code for the time-range object, when the periodic command is used. Due to this issue, the time-range object may have no effect. Therefore, depending on the access-list statement (permit or deny), an attacker could bypass the access list. An attacker could exploit this vulnerability by sending traffic through the affected system. Cisco has confirmed the vulnerability in a security notice; however, software updates are not available. Customers are advised to review the bug reports in the vendor announcements section for a current list of affected versions. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.