A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass the authentication phase on an 802.1x multi-auth port. The vulnerability is due to a logic change error introduced into the code. An attacker could exploit this vulnerability by trying to access an 802.1x multi-auth port after a successful supplicant has authenticated. An exploit could allow the attacker to bypass the 802.1x access controls and obtain access to the network. Cisco Bug IDs: CSCvg69701.

Project Subscriptions

Vendors Products
1120 Connected Grid Router Subscribe
1240 Connected Grid Router Subscribe
1905 Serial Integrated Services Router Subscribe
1906c Integrated Services Router Subscribe
1921 Integrated Services Router Subscribe
1941 Integrated Services Router Subscribe
1941w Integrated Services Router Subscribe
2010 Connected Grid Router Subscribe
2901 Integrated Services Router Subscribe
2911 Integrated Services Router Subscribe
2911a Integrated Services Router Subscribe
2921 Integrated Services Router Subscribe
2951 Integrated Services Router Subscribe
3925 Integrated Services Router Subscribe
3925e Integrated Services Router Subscribe
3945 Integrated Services Router Subscribe
3945e Integrated Services Router Subscribe
5915 Embedded Service Router Subscribe
5921 Embedded Services Router Subscribe
5940 Embedded Services Router Subscribe
800 Series Routers Subscribe
800m Integrated Services Router Subscribe
809 Industrial Integrated Services Router Subscribe
812 3g Integrated Services Router Subscribe
812 Cifi Integrated Services Router Subscribe
819 Hardened 3g Subscribe
819 Hardened Dual Radio 802.11n Wifi Integrated Services Router Subscribe
819 Hardened Integrated Services Router Subscribe
819 Integrated Services Router Subscribe
819 Non-hardened 4g Lte M2m Subscribe
819 Non-hardened Secure Multi-mode 4g Lte M2m Isr Router Subscribe
829 Industrial Integrated Services Router Subscribe
860vae-w Integrated Services Router Subscribe
861 Integrated Services Router Subscribe
861w Integrated Services Router Subscribe
866vae Integrated Services Router Subscribe
867vae Integrated Services Router Subscribe
880-voice Integrated Services Router Subscribe
881-cube Integrated Services Router Subscribe
881 3g Integrated Services Router Subscribe
881 Secure Fast Ethernet Subscribe
881w Integrated Services Router Subscribe
886va-cube Integrated Services Router Subscribe
886va-w Integrated Services Router Subscribe
886va Integrated Services Router Subscribe
886vag 3g Integrated Services Router Subscribe
887 Multi-mode Vdsl2\/asdl2\+ Pots Subscribe
887va-cube Integrated Services Router Subscribe
887va-w Integrated Services Router Subscribe
887va Integrated Services Router Subscribe
887vag 3g Integrated Services Router Subscribe
887vagw 3g Subscribe
887vam-w Integrated Services Router Subscribe
887vamg 3g Integrated Services Router Subscribe
888-cube Integrated Services Router Subscribe
888 Integrated Services Router Subscribe
888e-cube Integrated Services Router Subscribe
888e Integrated Services Router Subscribe
888eg 3g Integrated Services Router Subscribe
888w Integrated Services Router Subscribe
891-24x Integrated Services Router Subscribe
891 Integrated Services Router Subscribe
891w Integrated Services Router Subscribe
892 Integrated Services Router Subscribe
892f-cube Integrated Services Router Subscribe
892w Integrated Services Router Subscribe
896 Multi-mode Vdsl2\/adsl2\+ Isdn Subscribe
897 Multi-mode Vdsl2\/adsl2\+ Pots Subscribe
897 Multi-mode Vdsl2\/adsl2\+ Pots Annex M Subscribe
898 Secure G.shdsl Efm\/atm Subscribe
C866vae Integrated Services Router Subscribe
C867vae Integrated Services Router Subscribe
C881 Integrated Services Router Subscribe
C881w Integrated Services Router Subscribe
C886va Integrated Services Routers Subscribe
C886vaj Integrated Services Router Subscribe
C887va Integrated Services Routers Subscribe
C887vam Integrated Services Routers Subscribe
C888 Integrated Services Router Subscribe
C888ea Integrated Services Router Subscribe
C891f Integrated Services Routers Subscribe
C891fw Integrated Services Router Subscribe
C892fsp Integrated Services Router Subscribe
C896va Integrated Services Router Subscribe
C897va-m Integrated Services Router Subscribe
C897va Integrated Services Router Subscribe
C897vam-w Integrated Services Router Subscribe
C897vaw Integrated Services Router Subscribe
C898ea Integrated Services Router Subscribe
C899 Secure Gigabit Ethernet Subscribe
Vg204xm Analog Voice Gateway Subscribe
Vg350 Analog Voice Gateway Subscribe
Vg3x0 Analog Voice Gateway Subscribe
Rockwellautomation Subscribe
Stratix 5900 Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2018-0986 A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass the authentication phase on an 802.1x multi-auth port. The vulnerability is due to a logic change error introduced into the code. An attacker could exploit this vulnerability by trying to access an 802.1x multi-auth port after a successful supplicant has authenticated. An exploit could allow the attacker to bypass the 802.1x access controls and obtain access to the network. Cisco Bug IDs: CSCvg69701.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 02 Dec 2024 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-12-02T20:54:54.828Z

Reserved: 2017-11-27T00:00:00

Link: CVE-2018-0163

cve-icon Vulnrichment

Updated: 2024-08-05T03:14:16.957Z

cve-icon NVD

Status : Modified

Published: 2018-03-28T22:29:00.750

Modified: 2024-11-21T03:37:38.443

Link: CVE-2018-0163

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses