CVE-2003-0512

Cisco IOS <= 12.2 - Username Enumeration via Invalid Login Message

Title source: llm
STIX 2.1

Description

Cisco IOS 12.2 and earlier generates a "% Login invalid" message instead of prompting for a password when an invalid username is provided, which allows remote attackers to identify valid usernames on the system and conduct brute force password guessing, as reported for the Aironet Bridge.

References (5)

Core 5
Core References
Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/warp/public/707/cisco-sn-20030724-ios-enum.shtml
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5824
Vendor Advisory mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0056.html
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/886796

Scores

EPSS 0.0320
EPSS Percentile 86.8%

Details

CWE
CWE-310
Status published
Products (9)
cisco/ios 12.0\(24\)s1
cisco/ios 12.0\(24.2\)s
cisco/ios 12.2\(11\)ja1
cisco/ios 12.2\(14.5\)
cisco/ios 12.2\(14.5\)t
cisco/ios 12.2\(15\)zn
cisco/ios 12.2\(15.1\)s
cisco/ios 12.2\(16\)b
cisco/ios 12.2\(16.1\)b
Published Aug 27, 2003
Tracked Since Feb 18, 2026