CVE-2015-0607
Cisco Ios - Authentication Bypass
Title source: ruleDescription
The Authentication Proxy feature in Cisco IOS does not properly handle invalid AAA return codes from RADIUS and TACACS+ servers, which allows remote attackers to bypass authentication in opportunistic circumstances via a connection attempt that triggers an invalid code, as demonstrated by a connection attempt with a blank password, aka Bug IDs CSCuo09400 and CSCun16016.
References (4)
Scores
EPSS
0.0026
EPSS Percentile
49.6%
Classification
CWE
CWE-287
Status
draft
Affected Products (11)
cisco/ios
cisco/ios
cisco/ios
cisco/ios
cisco/ios
cisco/ios
cisco/ios
cisco/ios
cisco/ios
cisco/ios
cisco/ios
Timeline
Published
Mar 06, 2015
Tracked Since
Feb 18, 2026