Cisco IOS 12.2 and earlier generates a % Login invalid message instead of prompting for a password when an invalid username is provided, which allows remote attackers to identify valid usernames on the system and conduct brute force password guessing, as reported for the Aironet Bridge.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Ios | Cisco | 12.0(24)s1 (including) | 12.0(24)s1 (including) |
| Ios | Cisco | 12.0(24.2)s (including) | 12.0(24.2)s (including) |
| Ios | Cisco | 12.2(11)ja1 (including) | 12.2(11)ja1 (including) |
| Ios | Cisco | 12.2(14.5) (including) | 12.2(14.5) (including) |
| Ios | Cisco | 12.2(14.5)t (including) | 12.2(14.5)t (including) |
| Ios | Cisco | 12.2(15)zn (including) | 12.2(15)zn (including) |
| Ios | Cisco | 12.2(15.1)s (including) | 12.2(15.1)s (including) |
| Ios | Cisco | 12.2(16)b (including) | 12.2(16)b (including) |
| Ios | Cisco | 12.2(16.1)b (including) | 12.2(16.1)b (including) |