7.5
CVSSv2

CVE-2005-1058

Published: 02/05/2005 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cisco IOS 12.2T, 12.3 and 12.3T, when processing an ISAKMP profile that specifies XAUTH authentication after Phase 1 negotiation, may not process certain attributes in the ISAKMP profile that specifies XAUTH, which allows remote malicious users to bypass XAUTH and move to Phase 2 negotiations.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios 12.2t

cisco ios 12.3

cisco ios 12.3t

Vendor Advisories

Cisco Internetwork Operating System (IOS) Software release trains 122T, 123 and 123T may contain vulnerabilities in processing certain Internet Key Exchange (IKE) Xauth messages when configured to be an Easy VPN Server Successful exploitation of these vulnerabilities may permit an unauthorized user to complete authentication and pote ...