CVE-2015-0694: Medium severity Cisco IOS XR vulnerability
Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a single-host constraint, which allows remote attackers to bypass intended network-resource access restrictions by using an address that was not supposed to have been allowed, aka Bug ID CSCur28806.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0694?
CVE-2015-0694 has been classified as a high-severity vulnerability due to its potential to allow remote attackers to bypass access restrictions.
How do I fix CVE-2015-0694?
To fix CVE-2015-0694, you should upgrade your Cisco ASR 9000 devices to a version of IOS XR that addresses the ACL entry constraint issue.
Which devices are affected by CVE-2015-0694?
CVE-2015-0694 affects specific models of Cisco ASR 9000 devices running IOS XR version 5.3.0.BASE.
Can CVE-2015-0694 lead to unauthorized access?
Yes, CVE-2015-0694 can allow remote attackers to gain unauthorized access to network resources by bypassing access controls.
Is there a workaround for CVE-2015-0694?
There are no official workarounds for CVE-2015-0694; applying the necessary software update is the recommended approach.