CVE-2015-0607

The Authentication Proxy feature in Cisco IOS does not properly handle invalid AAA return codes from RADIUS and TACACS+ servers, which allows remote attackers to bypass authentication in opportunistic circumstances via a connection attempt that triggers an invalid code, as demonstrated by a connection attempt with a blank password, aka Bug IDs CSCuo09400 and CSCun16016.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:cisco:ios:15.4\(1\)t:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.4\(1\)t1:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.4\(1\)t2:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.4\(1\)t3:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.4\(1\)t4:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.4\(2\)t:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.4\(2\)t1:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.4\(2\)t2:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.4\(2\)t3:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.4\(100\)t:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.4t:*:*:*:*:*:*:*

History

21 Nov 2024, 02:23

Type Values Removed Values Added
References () http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0607 - Vendor Advisory () http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0607 - Vendor Advisory
References () http://tools.cisco.com/security/center/viewAlert.x?alertId=37711 - Vendor Advisory () http://tools.cisco.com/security/center/viewAlert.x?alertId=37711 - Vendor Advisory
References () http://www.securityfocus.com/bid/72794 - () http://www.securityfocus.com/bid/72794 -
References () http://www.securitytracker.com/id/1031817 - () http://www.securitytracker.com/id/1031817 -

Information

Published : 2015-03-06 03:00

Updated : 2024-11-21 02:23


NVD link : CVE-2015-0607

Mitre link : CVE-2015-0607

CVE.ORG link : CVE-2015-0607


JSON object : View

Products Affected

cisco

  • ios
CWE
CWE-287

Improper Authentication