QID 317197

Date Published: 2022-06-07

QID 317197: Cisco Internetwork Operating System (IOS) Authentication Bypass Vulnerability (cisco-sa-20020617-cmts-md5-bypass)

Cisco IOS Software allows the creation of a truncated, invalid configuration file that is improperly accepted as valid by the affected routers.

Affected Products
Cisco uBR7200 series and uBR7100 series Universal Broadband Routers
Note: This QID is not checking for the workaround.

QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.

Successful exploit could steal service by reconfiguring the cable modem to remove bandwidth restrictions

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-20020617-cmts-md5-bypass for more information.

    CVEs related to QID 317197

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-20020617-cmts-md5-bypass URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20020617-cmts-md5-bypass