ID

VAR-199710-0036


TITLE

Cisco IOS CHAP Authentication Vulnerabilities

Trust: 0.3

sources: BID: 693

DESCRIPTION

Cisco IOS software is reported prone to an authentication bypass vulnerability. This vulnerability presents itself in PPP CHAP authentication used by IOS. A remote attacker may bypass authentication to gain unauthorized access to vulnerable device. Cisco non-switch products with product numbers greater than or equal to 1000, AGS/AGS+/CGS/MGS, and CS-500 products are vulnerable to this issue. Another vulnerability related to the issue described above affects Cisco IOS/700 software. This issue can allow a remote attacker to establish an unauthorized PPP connection to a device that is running the vulnerable application. This attack requires the device to be using CHAP authentication and the attacker needs to modify code for a vulnerable PPP/CHAP implementation.

Trust: 0.3

sources: BID: 693

AFFECTED PRODUCTS

vendor:ciscomodel:ios/700scope:eqversion:4.1

Trust: 0.3

vendor:ciscomodel:iosscope:eqversion:9.1

Trust: 0.3

vendor:ciscomodel:ios 11.2pscope: - version: -

Trust: 0.3

vendor:ciscomodel:iosscope:eqversion:11.2

Trust: 0.3

vendor:ciscomodel:iosscope:eqversion:11.1

Trust: 0.3

vendor:ciscomodel:iosscope:eqversion:11.0

Trust: 0.3

vendor:ciscomodel:iosscope:eqversion:10.3

Trust: 0.3

vendor:ciscomodel:ios/700scope:neversion:4.1.2

Trust: 0.3

vendor:ciscomodel:ios pscope:neversion:11.2.8

Trust: 0.3

vendor:ciscomodel:iosscope:neversion:11.2.8

Trust: 0.3

vendor:ciscomodel:ios f1scope:neversion:11.2.4

Trust: 0.3

vendor:ciscomodel:ios iascope:neversion:11.1.13

Trust: 0.3

vendor:ciscomodel:ios cascope:neversion:11.1.13

Trust: 0.3

vendor:ciscomodel:ios aascope:neversion:11.1.13

Trust: 0.3

vendor:ciscomodel:iosscope:neversion:11.1.13

Trust: 0.3

vendor:ciscomodel:ios btscope:neversion:11.0.17

Trust: 0.3

vendor:ciscomodel:iosscope:neversion:11.0.17

Trust: 0.3

vendor:ciscomodel:ios ascope:neversion:10.3.19

Trust: 0.3

sources: BID: 693

THREAT TYPE

network

Trust: 0.3

sources: BID: 693

TYPE

Access Validation Error

Trust: 0.3

sources: BID: 693

EXTERNAL IDS

db:BIDid:693

Trust: 0.3

sources: BID: 693

REFERENCES

url:http://www.cisco.com/warp/public/707/sec_incident_response.shtml

Trust: 0.3

sources: BID: 693

CREDITS

This vulnerability was first reported by Cisco on 1 October 1997.

Trust: 0.3

sources: BID: 693

SOURCES

db:BIDid:693

LAST UPDATE DATE

2022-05-17T01:57:30.078000+00:00


SOURCES UPDATE DATE

db:BIDid:693date:1997-10-01T00:00:00

SOURCES RELEASE DATE

db:BIDid:693date:1997-10-01T00:00:00