CVE-2015-0607

The Authentication Proxy feature in Cisco IOS does not properly handle invalid AAA return codes from RADIUS and TACACS+ servers, which allows remote attackers to bypass authentication in opportunistic circumstances via a connection attempt that triggers an invalid code, as demonstrated by a connection attempt with a blank password, aka Bug IDs CSCuo09400 and CSCun16016.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:o:cisco:ios:15.4\(2\)t2:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.4\(2\)t3:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.4\(1\)t:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.4\(1\)t1:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.4\(1\)t2:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.4\(1\)t3:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.4t:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.4\(1\)t4:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.4\(2\)t:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.4\(100\)t:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.4\(2\)t1:*:*:*:*:*:*:*

Information

Published : 2015-03-05 19:00

Updated : 2015-03-06 08:17


NVD link : CVE-2015-0607

Mitre link : CVE-2015-0607


JSON object : View

CWE
CWE-287

Improper Authentication

Advertisement

dedicated server usa

Products Affected

cisco

  • ios