CVE-2005-2105

Cisco IOS 12.2T-12.4 - Unauthenticated AAA RADIUS Authentication Bypass via Long Username

Title source: llm
STIX 2.1

Description

Cisco IOS 12.2T through 12.4 allows remote attackers to bypass Authentication, Authorization, and Accounting (AAA) RADIUS authentication, if the fallback method is set to none, via a long username.

References (4)

Core 4
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/warp/public/707/cisco-sa-20050629-aaa.shtml
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5756
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/21190

Scores

EPSS 0.0259
EPSS Percentile 83.7%

Details

Status published
Products (50)
cisco/ios 12.2\(2\)xr
cisco/ios 12.2\(4\)xr
cisco/ios 12.2t
cisco/ios 12.2xb
cisco/ios 12.2xc
cisco/ios 12.2xd
cisco/ios 12.2xe
cisco/ios 12.2xf
cisco/ios 12.2xg
cisco/ios 12.2xh
... and 40 more
Published Jul 05, 2005
Tracked Since Feb 18, 2026