CVE-2014-2146 Information

Description

The Zone-Based Firewall (ZBFW) functionality in Cisco IOS possibly 15.4 and earlier and IOS XE possibly 3.13 and earlier mishandles zone checking for existing sessions which allows remote attackers to bypass intended resource-access restrictions via spoofed traffic that matches one of these sessions aka Bug IDs CSCun94946 and CSCun96847.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Reference

http://www.securityfocus.com/bid/93126 https://tools.cisco.com/security/center/viewAlert.x?alertId=39129

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

6.5

Share on: