>> Cisco Catalyst 6500 and Cisco 7600 Series Loopback Address Security Bypass
Title : Cisco Catalyst 6500 and Cisco 7600 Series Loopback Address Security Bypass VUPEN ID : VUPEN/ADV-2007-3276 CVE ID : CVE-2007-5134
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-09-27
Technical Description
A weakness has been identified in Cisco Catalyst 6500 and Cisco 7600 Series, which could be exploited by attackers to bypass security restrictions. This issue is caused by a design error where packets that are destined for the 127.0.0.0/8 network are received and processed by the Supervisor module, Multilayer Switch Feature Card (MSFC), or any other intelligent module without being filtered by existing access control lists, which could be exploited by authenticated attackers to bypass access control lists on systems that run Hybrid Mode (Catalyst OS (CatOS) software on the Supervisor Engine and IOS Software on the MSFC) and Native Mode (IOS Software on both the Supervisor Engine and the MSFC).