Cisco IOS Firewall Feature set, aka Context Based Access Control (CBAC) or Cisco Secure Integrated Software, for IOS 11.2P through 12.2T does not properly check the IP protocol type, which could allow remote attackers to bypass access control lists.
https://exchange.xforce.ibmcloud.com/vulnerabilities/7614
http://www.securityfocus.com/bid/3588
http://www.kb.cert.org/vuls/id/362483
http://www.cisco.com/warp/public/707/IOS-cbac-dynacl-pub.shtml