CVE-2005-1020
published 2005-05-02CVE-2005-1020: Secure Shell (SSH) 2 in Cisco IOS 12.0 through 12.3 allows remote attackers to cause a denial of service (device reload) (1) via a username that contains a…
PriorityP422high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
1.73%
74.9th percentile
Secure Shell (SSH) 2 in Cisco IOS 12.0 through 12.3 allows remote attackers to cause a denial of service (device reload) (1) via a username that contains a domain name when using a TACACS+ server to authenticate, (2) when a new SSH session is in the login phase and a currently logged in user issues a send command, or (3) when IOS is logging messages and an SSH session is terminated while the server is sending data.
Affected
338 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Vulnerabilities in Cisco IOS Secure Shell Server
vendor_cisco·2005-04-06
CVE-2005-1020 CWE-399 Vulnerabilities in Cisco IOS Secure Shell Server
Vulnerabilities in Cisco IOS Secure Shell Server
Certain release trains of Cisco Internetwork Operating System
(IOS)®, when configured to use the IOS Secure Shell
(SSH) server in combination with Terminal Access Controller Access Control
System Plus (TACACS+) as a means to perform remote management tasks on IOS
devices, may contain two vulnerabilities that can potentially cause IOS devices
to exhaust resources and reload. Repeated exploitation of these vulnerabilities
can result in a Denial of Service (DoS) condition. Use of SSH with other
authentication methods like Remote Authentication Dial In User Service (RADIUS)
and the local user database may also be affected.
Cisco has made free software available to address these
vulnerabilities for all affected customers. There are workarounds
Cisco
Vulnerabilities in Cisco IOS Secure Shell Server
vendor_cisco
CVE-2005-1020 Vulnerabilities in Cisco IOS Secure Shell Server
CVE-2005-1020: Vulnerabilities in Cisco IOS Secure Shell Server
Certain release trains of Cisco Internetwork Operating System (IOS) � , when configured to use the IOS Secure Shell (SSH) server in combination with Terminal Access Controller Access Control System Plus (TACACS+) as a means to perform remote management tasks on IOS devices, may contain two vulnerabilities that can potentially cause IOS devices to exhaust resources and reload. Repeated exploitation of these vulnerabilities can result in a Denial of Service (DoS) condition. Use of SSH with other authentication methods like Remote Authentication Dial In User Service (RADIUS) and the local user database may also be affected. Cisco has made free software available to address these vulnerabilities for all affected customers. There a
GHSA
GHSA-v2x2-6pmp-ggmv: Secure Shell (SSH) 2 in Cisco IOS 12
ghsa_unreviewed·2022-05-01
CVE-2005-1020 [HIGH] CWE-287 GHSA-v2x2-6pmp-ggmv: Secure Shell (SSH) 2 in Cisco IOS 12
Secure Shell (SSH) 2 in Cisco IOS 12.0 through 12.3 allows remote attackers to cause a denial of service (device reload) (1) via a username that contains a domain name when using a TACACS+ server to authenticate, (2) when a new SSH session is in the login phase and a currently logged in user issues a send command, or (3) when IOS is logging messages and an SSH session is terminated while the server is sending data.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/14854http://www.cisco.com/warp/public/707/cisco-sa-20050406-ssh.shtmlhttp://www.securityfocus.com/bid/13043http://www.securitytracker.com/alerts/2005/Apr/1013655.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/19987https://exchange.xforce.ibmcloud.com/vulnerabilities/19989https://exchange.xforce.ibmcloud.com/vulnerabilities/19990https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5455http://secunia.com/advisories/14854http://www.cisco.com/warp/public/707/cisco-sa-20050406-ssh.shtmlhttp://www.securityfocus.com/bid/13043http://www.securitytracker.com/alerts/2005/Apr/1013655.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/19987https://exchange.xforce.ibmcloud.com/vulnerabilities/19989https://exchange.xforce.ibmcloud.com/vulnerabilities/19990https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5455
2005-05-02
Published