CVE-2013-6979 Information

Description

The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS internal-network configuration which allows remote attackers to bypass authentication by leveraging access to a 192.168.x.2 source IP address aka Bug ID CSCuj90227.

Reference

http://osvdb.org/101351 http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6979 http://www.securityfocus.com/bid/64502 http://www.securitytracker.com/id/1029537 https://exchange.xforce.ibmcloud.com/vulnerabilities/89901

Share on: