Cisco NX-OS 6.1(2)I2(1) on Nexus 9000 switches does not properly process packet-drop policy checks for logged packets, which allows remote attackers to bypass intended access restrictions via a flood of packets matching a policy that contains the log keyword, aka Bug ID CSCuo02489.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1030676 | vdb entry |
http://tools.cisco.com/security/center/viewAlert.x?alertId=35181 | vendor advisory |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3330 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/95122 | vdb entry |
http://www.securityfocus.com/bid/69057 | vdb entry |