Cisco IOS on 12000 series routers contains a flaw that may allow a malicious user to bypass access control lists. The issue is triggered by lack of support for the "fragment" keyword by outbound ACLs. It is possible that the flaw may allow unauthorized traffic to traverse the network.
Classification
Unknown or Incomplete
Solution
Upgrade to version indicated in Cisco product matrix, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.