A flaw in Cisco Catalyst 6500 and 7600 series devices could be exploited to allow unauthorized personnel to bypass certain security restrictions.
According to a Cisco security response:
Cisco Catalyst 6500 and Cisco 7600 series devices use addresses from the 127.0.0.0/8 (loopback) range in the Ethernet Out-of-Band Channel (EOBC) for internal communication.
Addresses from this range that are used in the EOBC on Cisco Catalyst 6500 and Cisco 7600 series devices are accessible from outside of the system. The Supervisor module, Multilayer Switch Feature Card (MSFC), or any other intelligent module may receive and process packets that are destined for the 127.0.0.0/8 network. An attacker can exploit this behavior to bypass existing access control lists that do not filter 127.0.0.0/8 address range; however, an exploit will not allow an attacker to bypass authentication or authorization. Valid authentication credentials are still required to access the module in question.
Cisco has published a workaround in the response.
Secunia has rated the vulnerability as not critical.
Go here for more Cisco Security Advisories
Go here for more Cisco Security Responses
Go to Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, book giveaways, and more.
Recent Cisconet blog entries
Subscribe to Network World’s Cisco News Alert, which includes a weekly digest of all Cisco Subnet items




