CVE-2018-0163
28.03.2018, 22:29
A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass the authentication phase on an 802.1x multi-auth port. The vulnerability is due to a logic change error introduced into the code. An attacker could exploit this vulnerability by trying to access an 802.1x multi-auth port after a successful supplicant has authenticated. An exploit could allow the attacker to bypass the 802.1x access controls and obtain access to the network. Cisco Bug IDs: CSCvg69701.Enginsight
| Vendor | Product | Version |
|---|---|---|
| cisco | ios | 15.4\(3\)m6 |
| cisco | ios | 15.4\(3\)m6a |
| cisco | ios | 15.4\(3\)m7 |
| cisco | ios | 15.4\(3\)m7a |
| cisco | ios | 15.4\(3\)m8 |
| cisco | ios | 15.4\(3.0i\)m6 |
| cisco | ios | 15.5\(3\)m3 |
| cisco | ios | 15.5\(3\)m4 |
| cisco | ios | 15.5\(3\)m4a |
| cisco | ios | 15.5\(3\)m4b |
| cisco | ios | 15.5\(3\)m4c |
| cisco | ios | 15.5\(3\)m5 |
| cisco | ios | 15.5\(3\)m5a |
| cisco | ios | 15.5\(3\)m6 |
| cisco | ios | 15.5\(3\)m6a |
| cisco | ios | 15.6\(1\)t2 |
| cisco | ios | 15.6\(1\)t3 |
| cisco | ios | 15.6\(2\)t1 |
| cisco | ios | 15.6\(2\)t2 |
| cisco | ios | 15.6\(2\)t3 |
| cisco | ios | 15.6\(3\)m |
| cisco | ios | 15.6\(3\)m0a |
| cisco | ios | 15.6\(3\)m1 |
| cisco | ios | 15.6\(3\)m1a |
| cisco | ios | 15.6\(3\)m1b |
| cisco | ios | 15.6\(3\)m2 |
| cisco | ios | 15.6\(3\)m2a |
| cisco | ios | 15.6\(3\)m3 |
| cisco | ios | 15.6\(3\)m3a |
| cisco | ios | 15.7\(3\)m |
| cisco | ios | 15.7\(3\)m0a |
| cisco | ios | 15.7\(3\)m1 |
| cisco | ios | 15.7\(3\)m2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration