CVE Vulnerabilities

CVE-2007-4632

Improper Authentication

Published: Aug 31, 2007 | Modified: Oct 26, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:A/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Cisco IOS 12.2E, 12.2F, and 12.2S places a no login line into the VTY configuration when an administrator makes certain changes to a (1) VTY/AUX or (2) CONSOLE setting on a device without AAA enabled, which allows remote attackers to bypass authentication and obtain a terminal session, a different vulnerability than CVE-1999-0293 and CVE-2005-2105.

Weakness

When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Ios Cisco 12.2e 12.2e
Ios Cisco 12.2f 12.2f
Ios Cisco 12.2s 12.2s

Potential Mitigations

References