Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rvr7-79c9-w4jr

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS internal-network configuration, which allows remote attackers to bypass authentication by leveraging access to a 192.168.x.2 source IP address, aka Bug ID CSCuj90227.

The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS internal-network configuration, which allows remote attackers to bypass authentication by leveraging access to a 192.168.x.2 source IP address, aka Bug ID CSCuj90227.

EPSS

Процентиль: 55%
0.00325
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
около 12 лет назад

The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS internal-network configuration, which allows remote attackers to bypass authentication by leveraging access to a 192.168.x.2 source IP address, aka Bug ID CSCuj90227.

EPSS

Процентиль: 55%
0.00325
Низкий

Дефекты

CWE-287