CVE-2015-0694: Cisco Asr 9001
Medium severity, CVSS 5.0. EPSS: 1.6% chance of exploitation in the next 30 days.
Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a single-host constraint, which allows remote attackers to bypass intended network-resource access restrictions by using an address that was not supposed to have been allowed, aka Bug ID CSCur28806.
Affected products
- Cisco Asr 9001
- Cisco Asr 9006
- Cisco Asr 9010
- Cisco Asr 9904
- Cisco Asr 9912
- Cisco Asr 9922
- Cisco IOS XR: version 5.3.0_base only
Published 2015-04-11. Last modified 2026-06-17.