Cisco IOS 12.2T, 12.3 and 12.3T, when processing an ISAKMP profile that specifies XAUTH authentication after Phase 1 negotiation, may not process certain attributes in the ISAKMP profile that specifies XAUTH, which allows remote attackers to bypass XAUTH and move to Phase 2 negotiations.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ios | Cisco | 12.2t (including) | 12.2t (including) |
Ios | Cisco | 12.3 (including) | 12.3 (including) |
Ios | Cisco | 12.3t (including) | 12.3t (including) |