Cisco IOS CHAP Authentication Vulnerabilities
BID:693
Info
Cisco IOS CHAP Authentication Vulnerabilities
| Bugtraq ID: | 693 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 1997 12:00AM |
| Updated: | Oct 01 1997 12:00AM |
| Credit: | This vulnerability was first reported by Cisco on 1 October 1997. |
| Vulnerable: |
Cisco IOS/700 4.1 Cisco IOS 9.1 Cisco IOS 11.2P Cisco IOS 11.2 Cisco IOS 11.1 Cisco IOS 11.0 Cisco IOS 10.3 |
| Not Vulnerable: |
Cisco IOS/700 4.1.2 Cisco IOS 11.2.8 P Cisco IOS 11.2.8 Cisco IOS 11.2.4 F1 Cisco IOS 11.1.13 IA Cisco IOS 11.1.13 CA Cisco IOS 11.1.13 AA Cisco IOS 11.1.13 Cisco IOS 11.0.17 BT Cisco IOS 11.0.17 Cisco IOS 10.3.19 a |
Discussion
Cisco IOS CHAP Authentication Vulnerabilities
Cisco IOS software is reported prone to an authentication bypass vulnerability. This vulnerability presents itself in PPP CHAP authentication used by IOS. A remote attacker may bypass authentication to gain unauthorized access to vulnerable device. Cisco non-switch products with product numbers greater than or equal to 1000, AGS/AGS+/CGS/MGS, and CS-500 products are vulnerable to this issue.
Another vulnerability related to the issue described above affects Cisco IOS/700 software. This issue can allow a remote attacker to establish an unauthorized PPP connection to a device that is running the vulnerable application. This attack requires the device to be using CHAP authentication and the attacker needs to modify code for a vulnerable PPP/CHAP implementation.
Cisco IOS software is reported prone to an authentication bypass vulnerability. This vulnerability presents itself in PPP CHAP authentication used by IOS. A remote attacker may bypass authentication to gain unauthorized access to vulnerable device. Cisco non-switch products with product numbers greater than or equal to 1000, AGS/AGS+/CGS/MGS, and CS-500 products are vulnerable to this issue.
Another vulnerability related to the issue described above affects Cisco IOS/700 software. This issue can allow a remote attacker to establish an unauthorized PPP connection to a device that is running the vulnerable application. This attack requires the device to be using CHAP authentication and the attacker needs to modify code for a vulnerable PPP/CHAP implementation.
Exploit / POC
Cisco IOS CHAP Authentication Vulnerabilities
See discussion.
See discussion.
Solution / Fix
Cisco IOS CHAP Authentication Vulnerabilities
References
Cisco IOS CHAP Authentication Vulnerabilities
References:
References:
- Cisco Product Security Incident Response (Cisco Systems)