Lucene search

K
cveCiscoCVE-2015-0607
HistoryMar 06, 2015 - 3:00 a.m.

CVE-2015-0607

2015-03-0603:00:13
CWE-287
cisco
web.nvd.nist.gov
23
cisco
ios
authentication proxy
cve-2015-0607
radius
tacacs+
bypass
authentication
remote attackers
bug ids
cscuo09400
cscun16016
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

7

Confidence

Low

EPSS

0.004

Percentile

72.6%

The Authentication Proxy feature in Cisco IOS does not properly handle invalid AAA return codes from RADIUS and TACACS+ servers, which allows remote attackers to bypass authentication in opportunistic circumstances via a connection attempt that triggers an invalid code, as demonstrated by a connection attempt with a blank password, aka Bug IDs CSCuo09400 and CSCun16016.

Affected configurations

Nvd
Node
ciscoiosMatch15.4\(1\)t
OR
ciscoiosMatch15.4\(1\)t1
OR
ciscoiosMatch15.4\(1\)t2
OR
ciscoiosMatch15.4\(1\)t3
OR
ciscoiosMatch15.4\(1\)t4
OR
ciscoiosMatch15.4\(2\)t
OR
ciscoiosMatch15.4\(2\)t1
OR
ciscoiosMatch15.4\(2\)t2
OR
ciscoiosMatch15.4\(2\)t3
OR
ciscoiosMatch15.4\(100\)t
OR
ciscoiosMatch15.4t
VendorProductVersionCPE
ciscoios15.4(1)tcpe:2.3:o:cisco:ios:15.4\(1\)t:*:*:*:*:*:*:*
ciscoios15.4(1)t1cpe:2.3:o:cisco:ios:15.4\(1\)t1:*:*:*:*:*:*:*
ciscoios15.4(1)t2cpe:2.3:o:cisco:ios:15.4\(1\)t2:*:*:*:*:*:*:*
ciscoios15.4(1)t3cpe:2.3:o:cisco:ios:15.4\(1\)t3:*:*:*:*:*:*:*
ciscoios15.4(1)t4cpe:2.3:o:cisco:ios:15.4\(1\)t4:*:*:*:*:*:*:*
ciscoios15.4(2)tcpe:2.3:o:cisco:ios:15.4\(2\)t:*:*:*:*:*:*:*
ciscoios15.4(2)t1cpe:2.3:o:cisco:ios:15.4\(2\)t1:*:*:*:*:*:*:*
ciscoios15.4(2)t2cpe:2.3:o:cisco:ios:15.4\(2\)t2:*:*:*:*:*:*:*
ciscoios15.4(2)t3cpe:2.3:o:cisco:ios:15.4\(2\)t3:*:*:*:*:*:*:*
ciscoios15.4(100)tcpe:2.3:o:cisco:ios:15.4\(100\)t:*:*:*:*:*:*:*
Rows per page:
1-10 of 111

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

7

Confidence

Low

EPSS

0.004

Percentile

72.6%

Related for CVE-2015-0607