CVE-2005-1057
published 2005-05-02CVE-2005-1057: Cisco IOS 12.2T, 12.3 and 12.3T, when using Easy VPN Server XAUTH version 6 authentication, allows remote attackers to bypass authentication via a "malformed…
PriorityP339high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.44%
70.5th percentile
Cisco IOS 12.2T, 12.3 and 12.3T, when using Easy VPN Server XAUTH version 6 authentication, allows remote attackers to bypass authentication via a "malformed packet."
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Vulnerabilities in the Internet Key Exchange Xauth Implementation
vendor_cisco·2005-04-06
CVE-2005-1057 CWE-287 Vulnerabilities in the Internet Key Exchange Xauth Implementation
Vulnerabilities in the Internet Key Exchange Xauth Implementation
Cisco Internetwork Operating System (IOS) Software release trains
12.2T, 12.3 and 12.3T may contain vulnerabilities in processing certain
Internet Key Exchange (IKE) Xauth messages when configured to be an Easy VPN
Server.
Successful exploitation of these vulnerabilities may permit an
unauthorized user to complete authentication and potentially access network
resources.
This advisory will be posted to
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20050406-xauth
Cisco has made free software available to address this vulnerability
for affected customers.
Cisco
Vulnerabilities in the Internet Key Exchange Xauth Implementation
vendor_cisco
CVE-2005-1057 Vulnerabilities in the Internet Key Exchange Xauth Implementation
CVE-2005-1057: Vulnerabilities in the Internet Key Exchange Xauth Implementation
Cisco Internetwork Operating System (IOS) Software release trains 12.2T, 12.3 and 12.3T may contain vulnerabilities in processing certain Internet Key Exchange (IKE) Xauth messages when configured to be an Easy VPN Server. Successful exploitation of these vulnerabilities may permit an unauthorized user to complete authentication and potentially access network resources. This advisory will be posted to https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20050406-xauth Cisco has made free software available to address this vulnerability for affected customers.
CWE: CWE-287, CWE-287
Bug IDs: CSCeg00277, CSCin82407, CSCin82407, CSCeg00277
GHSA
GHSA-85g4-355g-r556: Cisco IOS 12
ghsa_unreviewed·2022-05-01
CVE-2005-1057 [HIGH] GHSA-85g4-355g-r556: Cisco IOS 12
Cisco IOS 12.2T, 12.3 and 12.3T, when using Easy VPN Server XAUTH version 6 authentication, allows remote attackers to bypass authentication via a "malformed packet."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.cisco.com/warp/public/707/cisco-sa-20050406-xauth.shtmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5852http://www.cisco.com/warp/public/707/cisco-sa-20050406-xauth.shtmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5852
2005-05-02
Published