Description
A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass the authentication phase on an 802.1x multi-auth port. The vulnerability is due to a logic change error introduced into the code. An attacker could exploit this vulnerability by trying to access an 802.1x multi-auth port after a successful supplicant has authenticated. An exploit could allow the attacker to bypass the 802.1x access controls and obtain access to the network. Cisco Bug IDs: CSCvg69701.
Published: 2018-03-28
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-0986 A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass the authentication phase on an 802.1x multi-auth port. The vulnerability is due to a logic change error introduced into the code. An attacker could exploit this vulnerability by trying to access an 802.1x multi-auth port after a successful supplicant has authenticated. An exploit could allow the attacker to bypass the 802.1x access controls and obtain access to the network. Cisco Bug IDs: CSCvg69701.
History

Mon, 02 Dec 2024 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco 1120 Connected Grid Router 1240 Connected Grid Router 1905 Serial Integrated Services Router 1906c Integrated Services Router 1921 Integrated Services Router 1941 Integrated Services Router 1941w Integrated Services Router 2010 Connected Grid Router 2901 Integrated Services Router 2911 Integrated Services Router 2911a Integrated Services Router 2921 Integrated Services Router 2951 Integrated Services Router 3925 Integrated Services Router 3925e Integrated Services Router 3945 Integrated Services Router 3945e Integrated Services Router 5915 Embedded Service Router 5921 Embedded Services Router 5940 Embedded Services Router 800 Series Routers 800m Integrated Services Router 809 Industrial Integrated Services Router 812 3g Integrated Services Router 812 Cifi Integrated Services Router 819 Hardened 3g 819 Hardened Dual Radio 802.11n Wifi Integrated Services Router 819 Hardened Integrated Services Router 819 Integrated Services Router 819 Non-hardened 4g Lte M2m 819 Non-hardened Secure Multi-mode 4g Lte M2m Isr Router 829 Industrial Integrated Services Router 860vae-w Integrated Services Router 861 Integrated Services Router 861w Integrated Services Router 866vae Integrated Services Router 867vae Integrated Services Router 880-voice Integrated Services Router 881-cube Integrated Services Router 881 3g 881 3g Integrated Services Router 881 Secure Fast Ethernet 881w Integrated Services Router 886va-cube Integrated Services Router 886va-w Integrated Services Router 886va Integrated Services Router 886vag 3g Integrated Services Router 887 Multi-mode Vdsl2\/asdl2\+ Pots 887va-cube Integrated Services Router 887va-w Integrated Services Router 887va Integrated Services Router 887vag 3g Integrated Services Router 887vagw 3g 887vam-w Integrated Services Router 887vamg 3g Integrated Services Router 888-cube Integrated Services Router 888 Integrated Services Router 888e-cube Integrated Services Router 888e Integrated Services Router 888eg 3g Integrated Services Router 888w Integrated Services Router 891-24x Integrated Services Router 891 Integrated Services Router 891w Integrated Services Router 892 Integrated Services Router 892f-cube Integrated Services Router 892w Integrated Services Router 896 Multi-mode Vdsl2\/adsl2\+ Isdn 897 Multi-mode Vdsl2\/adsl2\+ Pots 897 Multi-mode Vdsl2\/adsl2\+ Pots Annex M 898 Secure G.shdsl Efm\/atm C866vae Integrated Services Router C867vae Integrated Services Router C881 Integrated Services Router C881w Integrated Services Router C886va Integrated Services Routers C886vaj Integrated Services Router C887va Integrated Services Routers C887vam Integrated Services Routers C888 Integrated Services Router C888ea Integrated Services Router C891f Integrated Services Routers C891fw Integrated Services Router C892fsp Integrated Services Router C896va Integrated Services Router C897va-m Integrated Services Router C897va Integrated Services Router C897vam-w Integrated Services Router C897vaw Integrated Services Router C898ea Integrated Services Router C899 Secure Gigabit Ethernet Ios Vg204xm Analog Voice Gateway Vg350 Analog Voice Gateway Vg3x0 Analog Voice Gateway
Rockwellautomation Stratix 5900
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-12-02T20:54:54.828Z

Reserved: 2017-11-27T00:00:00.000Z

Link: CVE-2018-0163

cve-icon Vulnrichment

Updated: 2024-08-05T03:14:16.957Z

cve-icon NVD

Status : Modified

Published: 2018-03-28T22:29:00.750

Modified: 2024-11-21T03:37:38.443

Link: CVE-2018-0163

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses