
449
Caveats for Cisco IOS Release 12.2(33)SRD through 12.2(33)SRD8
OL-10394-05 Rev. R0
• CSCts38429
The Cisco IOS Software Internet Key Exchange (IKE) feature contains a denial of service (DoS)
vulnerability.
Cisco has released free software updates that address this vulnerability. This advisory is available at
the following link:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-ike
Resolved Caveats—Cisco IOS Release 12.2(33)SRD7
Cisco IOS Release 12.2(33)SRD7 is a rebuild release for Cisco IOS Release 12.2(33)SRD. The caveats
in this section are resolved in Cisco IOS Release 12.2(33)SRD7 but may be open in previous Cisco IOS
releases.
• CSCsw77313
Symptoms: After a successful login to a router, issuing the login command with a different username
may result in the session appearing to execute with the new username even if the login attempt is
unsuccessful. The new username will be reported by commands such as show users, and it will be
used in AAA processing and reporting. The privilege level of the new user is not changed. It stays
at the privilege level of the original user.
Conditions: The symptom is observed with authorization enabled with the aaa authorization
configuration command.
Workaround: Use “aaa authorization” to disable the login exec command.
• CSCtg26538
Symptoms: After applying a CoPP policy any traffic that would arrive at the CPU with an MPLS
label is not classified and is classified in the class-default.
Conditions: This symptom will be seen for any traffic arriving at the CPU with a MPLS label. The
easiest manifestation of this would be to use a loopback in a VRF for management. Any traffic
destined to or sourced from that loopback interface will not match the expected CoPP policy
classification. For example:
interface loopback0
ip vrf forwarding red
ip address 192.168.1.1 255.255.255.255
!
access-list 101 permit ip any host 192.168.1.1
!
class-map loopback-traffic
match access-group 101
!
policy-map loopback-copp
class loopback-traffic
police 8000
!
control-plane
service-policy in loopback-copp
Comentarios a estos manuales