Advisories Blog | G5 Cyber Security

cisco-sr-20070926-lb.txt

Cisco Security Advisory – Cisco Catalyst 6500 and Cisco 7600 series devices use addresses from the 127.0.0.0/8 (loopback) range in the Ethernet Out-of-Band Channel (EOBC) for internal communication. Addresses from this range that are used in the EOBC on Cisco Catalyst 6500 and Cisco 7600 series devices are accessible from outside of the system. The Supervisor module, Multilayer Switch Feature Card (MSFC), or any other intelligent module may receive and process packets that are destined for the 127.0.0.0/8 network. An attacker can exploit this behavior to bypass existing access control lists that do not filter 127.0.0.0/8 address range; however, an exploit will not allow an attacker to bypass authentication or authorization. Valid authentication credentials are still required to access the module in question.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/59641/cisco-sr-20070926-lb.txt

Source: https://packetstormsecurity.com/files/59641/cisco-sr-20070926-lb.txt.html

Exit mobile version