Skip to main content

Cisco IOS/IOS XE SSHv2 RSA Authentication Vulenerability

Last Update Date: 24 Sep 2015 10:24 Release Date: 24 Sep 2015 3678 Views

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

A vulnerability has been identified in Cisco IOS/IOS XE. A remote user can bypass authentication.

 

A remote user with knowledge of a username configured for SSHv2 RSA authentication and with access to the target user's public key can supply a specially crafted RSA private key to bypass authentication and access the target device with the privileges of the target user configured for the virtual teletype (VTY) line.


Impact

  • Security Restriction Bypass

System / Technologies affected

  • IOS/IOS XE

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix.

Vulnerability Identifier


Source


Related Link