The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS internal-network configuration, which allows remote attackers to bypass authentication by leveraging access to a 192.168.x.2 source IP address, aka Bug ID CSCuj90227.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/89901 | vdb entry |
http://www.securitytracker.com/id/1029537 | vdb entry third party advisory |
http://osvdb.org/101351 | vdb entry |
http://www.securityfocus.com/bid/64502 | vdb entry third party advisory |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6979 | vendor advisory |