---
id: CVE-1999-1466
title: >-
  Vulnerability in Cisco routers versions 8.2 through 9.1 allows remote
  attackers to bypass access control lists when extended IP access lists are
  used on certain interfaces, the IP route cache is enabled, and the access list
  uses the "est…
summary: >-
  Vulnerability in Cisco routers versions 8.2 through 9.1 allows remote
  attackers to bypass access control lists when extended IP access lists are
  used on certain interfaces, the IP route cache is enabled, and the access list
  uses the "est…
severity: high
cvss: 7.5
cvssVector: 'AV:N/AC:L/Au:N/C:P/I:P/A:P'
published: '1992-12-10'
updated: '2026-06-16'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-1999-1466'
references:
  - url: 'http://www.cert.org/advisories/CA-1992-20.html'
    label: cve@mitre.org
  - url: 'http://www.securityfocus.com/bid/53'
    label: cve@mitre.org
  - url: 'http://www.cert.org/advisories/CA-1992-20.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/53'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.02319
epssPercentile: 0.82711
ingestedAt: '2026-06-19T03:39:00.710Z'
---

## Overview

Vulnerability in Cisco routers versions 8.2 through 9.1 allows remote attackers to bypass access control lists when extended IP access lists are used on certain interfaces, the IP route cache is enabled, and the access list uses the "established" keyword.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
