CVE-2015-0607
Cisco IOS - Authentication Bypass via Invalid AAA Return Code Handling
Title source: llmDescription
The Authentication Proxy feature in Cisco IOS does not properly handle invalid AAA return codes from RADIUS and TACACS+ servers, which allows remote attackers to bypass authentication in opportunistic circumstances via a connection attempt that triggers an invalid code, as demonstrated by a connection attempt with a blank password, aka Bug IDs CSCuo09400 and CSCun16016.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/72794
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1031817
Vendor Advisory x_refsource_confirm
http://tools.cisco.com/security/center/viewAlert.x?alertId=37711
Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0607
Scores
EPSS
0.0197
EPSS Percentile
77.9%
Details
CWE
CWE-287
Status
published
Products (11)
cisco/ios
15.4\(1\)t
cisco/ios
15.4\(1\)t1
cisco/ios
15.4\(1\)t2
cisco/ios
15.4\(1\)t3
cisco/ios
15.4\(1\)t4
cisco/ios
15.4\(2\)t
cisco/ios
15.4\(2\)t1
cisco/ios
15.4\(2\)t2
cisco/ios
15.4\(2\)t3
cisco/ios
15.4\(100\)t
... and 1 more
Published
Mar 06, 2015
Tracked Since
Feb 18, 2026