CVE-2015-0607
Published Mar 6, 2015
Last updated 10 years ago
Overview
- Description
- The Authentication Proxy feature in Cisco IOS does not properly handle invalid AAA return codes from RADIUS and TACACS+ servers, which allows remote attackers to bypass authentication in opportunistic circumstances via a connection attempt that triggers an invalid code, as demonstrated by a connection attempt with a blank password, aka Bug IDs CSCuo09400 and CSCun16016.
- Source
- ykramarz@cisco.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-287
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:cisco:ios:15.4\\(1\\)t:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A0B856BB-0FFE-4A92-9CE7-D71B6C611CD3" }, { "criteria": "cpe:2.3:o:cisco:ios:15.4\\(1\\)t1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C1EE552E-226C-46DE-9861-CB148AD8FB44" }, { "criteria": "cpe:2.3:o:cisco:ios:15.4\\(1\\)t2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CAF02C8E-9BB2-4DC2-8BF1-932835191F09" }, { "criteria": "cpe:2.3:o:cisco:ios:15.4\\(1\\)t3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C1B86D1-344A-470D-8A35-BD8A9ABE9D9A" }, { "criteria": "cpe:2.3:o:cisco:ios:15.4\\(1\\)t4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C5AC88EB-7A67-4CDE-9C69-94734966E677" }, { "criteria": "cpe:2.3:o:cisco:ios:15.4\\(2\\)t:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "74E1226B-46CF-4C82-911A-86C818A75DFA" }, { "criteria": "cpe:2.3:o:cisco:ios:15.4\\(2\\)t1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "100DA24F-464E-4273-83DF-6428D0ED6641" }, { "criteria": "cpe:2.3:o:cisco:ios:15.4\\(2\\)t2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "063C0C47-25EB-4AA4-9332-8E43CD60FF39" }, { "criteria": "cpe:2.3:o:cisco:ios:15.4\\(2\\)t3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A6004A94-FF96-4A34-B3CC-D4B4E555CFB4" }, { "criteria": "cpe:2.3:o:cisco:ios:15.4\\(100\\)t:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "844CB97B-B6DE-44E5-B1DD-EA4976E58A84" }, { "criteria": "cpe:2.3:o:cisco:ios:15.4t:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "512D35A9-14FB-4797-88F1-AAE6F1232057" } ], "operator": "OR" } ] } ]