CVE-2005-2105
published 2005-07-05CVE-2005-2105: Cisco IOS 12.2T through 12.4 allows remote attackers to bypass Authentication, Authorization, and Accounting (AAA) RADIUS authentication, if the fallback…
PriorityP342high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.59%
83.7th percentile
Cisco IOS 12.2T through 12.4 allows remote attackers to bypass Authentication, Authorization, and Accounting (AAA) RADIUS authentication, if the fallback method is set to none, via a long username.
Affected
95 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x65w-rc3c-c7r6: Cisco IOS 12
ghsa_unreviewed·2022-05-01
CVE-2005-2105 [HIGH] GHSA-x65w-rc3c-c7r6: Cisco IOS 12
Cisco IOS 12.2T through 12.4 allows remote attackers to bypass Authentication, Authorization, and Accounting (AAA) RADIUS authentication, if the fallback method is set to none, via a long username.
GHSA
GHSA-wmmp-2f22-959m: Cisco IOS 12
ghsa_unreviewed·2022-05-01·CVSS 7.5
CVE-2007-4632 [HIGH] CWE-287 GHSA-wmmp-2f22-959m: Cisco IOS 12
Cisco IOS 12.2E, 12.2F, and 12.2S places a "no login" line into the VTY configuration when an administrator makes certain changes to a (1) VTY/AUX or (2) CONSOLE setting on a device without AAA enabled, which allows remote attackers to bypass authentication and obtain a terminal session, a different vulnerability than CVE-1999-0293 and CVE-2005-2105.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.cisco.com/warp/public/707/cisco-sa-20050629-aaa.shtmlhttp://www.securitytracker.com/alerts/2005/Jun/1014330.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/21190https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5756http://www.cisco.com/warp/public/707/cisco-sa-20050629-aaa.shtmlhttp://www.securitytracker.com/alerts/2005/Jun/1014330.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/21190https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5756
2005-07-05
Published