Cisco IOS contains a flaw that may allow a malicious user to bypass access control lists. The issue is caused by incorrect parses of extended ACLs which use the "tacacs" and "tacacs-ds" keywords. It is possible that the flaw may allow unauthorized traffic to traverse the network.
Classification
Attack Type:
Authentication Management,
Input Manipulation
Impact:
Loss of Integrity
Disclosure:
Vendor Verified
Solution
Upgrade to version indicated by Cisco product matrixx, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.