Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows remote attackers to bypass intended access restrictions via a crafted series of packets, aka Bug ID CSCug90143.
| Software | From | Fixed in |
|---|---|---|
| cisco / ios | - | 12.4\(24\)mdb14.x |
| cisco / ios | 12.4(24)md | 12.4(24)md.x |
| cisco / ios | 12.4(24)md1 | 12.4(24)md1.x |
| cisco / ios | 12.4(24)md2 | 12.4(24)md2.x |
| cisco / ios | 12.4(24)md3 | 12.4(24)md3.x |
| cisco / ios | 12.4(24)md4 | 12.4(24)md4.x |
| cisco / ios | 12.4(24)md5 | 12.4(24)md5.x |
| cisco / ios | 12.4(24)md5a | 12.4(24)md5a.x |
| cisco / ios | 12.4(24)md6 | 12.4(24)md6.x |
| cisco / ios | 12.4(24)md7 | 12.4(24)md7.x |
| cisco / ios | 12.4(24)md8 | 12.4(24)md8.x |
| cisco / ios | 12.4(24)md9 | 12.4(24)md9.x |
| cisco / ios | 12.4(24)mda6 | 12.4(24)mda6.x |
| cisco / ios | 12.4(24)mda7 | 12.4(24)mda7.x |
| cisco / ios | 12.4(24)mda8 | 12.4(24)mda8.x |
| cisco / ios | 12.4(24)mda9 | 12.4(24)mda9.x |
| cisco / ios | 12.4(24)mda10 | 12.4(24)mda10.x |
| cisco / ios | 12.4(24)mda11 | 12.4(24)mda11.x |
| cisco / ios | 12.4(24)mda12 | 12.4(24)mda12.x |
| cisco / ios | 12.4(24)mda13 | 12.4(24)mda13.x |
| cisco / ios | 12.4(24)mdb10 | 12.4(24)mdb10.x |
| cisco / ios | 12.4(24)mdb11 | 12.4(24)mdb11.x |
| cisco / ios | 12.4(24)mdb12 | 12.4(24)mdb12.x |
| cisco / ios | 12.4(24)mdb13 | 12.4(24)mdb13.x |
| cisco / ios | 12.4mda12 | 12.4mda12.x |