4
CVSSv2

CVE-2015-6365

Published: 14/11/2015 Updated: 07/12/2016
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

A vulnerability in Cisco devices that are running Cisco IOS Software Release 15.2(04)M or Cisco IOS Software Release 15.4(03)M and are configured to use access control lists (ACLs) could allow a user who is connected to an authenticated PPP session to bypass ACLs that are configured on virtual PPP interfaces, if the ACL on the physical interface permits the traffic to pass. The vulnerability is due to the physical interface ignoring virtual PPP ACLs. An attacker could exploit this vulnerability to bypass virtual PPP ACLs and pass denied traffic across virtual PPP interfaces. A successful exploit could allow the malicious user to pass traffic as if the ACLs do not exist. Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available. This advisory is available at the following link: tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151112-ios1

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios 15.2\\(4\\)m

cisco ios 15.4\\(3\\)m

Vendor Advisories

A vulnerability in Cisco devices that are running Cisco IOS Software Release 152(04)M or Cisco IOS Software Release 154(03)M and are configured to use access control lists (ACLs) could allow a user who is connected to an authenticated PPP session to bypass ACLs that are configured on virtual PPP interfaces, if the ACL on the physical interface pe ...