>> Cisco IOS GRE Decapsulation Access Control Lists Security Bypass Vulnerability
Title : Cisco IOS GRE Decapsulation Access Control Lists Security Bypass Vulnerability VUPEN ID : VUPEN/ADV-2006-3502 CVE ID : CVE-2006-4650
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-09-07
Technical Description
A vulnerability has been identified in Cisco IOS, which could be exploited by remote attackers to bypass security restrictions. This flaw is due to an error where the offset field is not verified when processing and decapsulating GRE packets with source routing information, which could be exploited by attackers to bypass access-control lists on the router via specially crafted packets.