CVE-2003-0512
Cisco IOS <= 12.2 - Username Enumeration via Invalid Login Message
Title source: llmDescription
Cisco IOS 12.2 and earlier generates a "% Login invalid" message instead of prompting for a password when an invalid username is provided, which allows remote attackers to identify valid usernames on the system and conduct brute force password guessing, as reported for the Aironet Bridge.
References (5)
Core 5
Core References
Various Sources x_refsource_misc
http://www.vigilante.com/inetsecurity/advisories/VIGILANTE-2003002.htm
Vendor Advisory vendor-advisory
x_refsource_cisco
http://www.cisco.com/warp/public/707/cisco-sn-20030724-ios-enum.shtml
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5824
Vendor Advisory mailing-list
x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0056.html
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/886796
Scores
EPSS
0.0320
EPSS Percentile
86.8%
Details
CWE
CWE-310
Status
published
Products (9)
cisco/ios
12.0\(24\)s1
cisco/ios
12.0\(24.2\)s
cisco/ios
12.2\(11\)ja1
cisco/ios
12.2\(14.5\)
cisco/ios
12.2\(14.5\)t
cisco/ios
12.2\(15\)zn
cisco/ios
12.2\(15.1\)s
cisco/ios
12.2\(16\)b
cisco/ios
12.2\(16.1\)b
Published
Aug 27, 2003
Tracked Since
Feb 18, 2026