A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a virtual routing and forwarding (VRF) instance despite the absence of the vrf-also keyword in the access-class configuration. The vulnerability is due to a missing check in the SSH server. An attacker could use this vulnerability to open an SSH connection to an affected Cisco IOS or IOS XE device with a source address belonging to a VRF instance. Once connected, the attacker would still need to provide valid credentials to access the device.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 19 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-19T19:18:45.475Z

Reserved: 2017-11-27T00:00:00

Link: CVE-2018-0484

cve-icon Vulnrichment

Updated: 2024-08-05T03:28:11.002Z

cve-icon NVD

Status : Modified

Published: 2019-01-10T18:29:00.377

Modified: 2024-11-21T03:38:19.630

Link: CVE-2018-0484

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.