The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generates a random internal name for an ACL that is also used as a hidden user name and password, which allows remote attackers to gain privileges by sniffing the username from the cleartext portion of a RADIUS session, then using the password to log in to another device that uses CS ACS.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2005-12-22T11:00:00

Updated: 2018-10-19T14:57:01

Reserved: 2005-12-22T00:00:00


Link: CVE-2005-4499

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2005-12-22T11:03:00.000

Modified: 2023-08-11T18:54:47.730


Link: CVE-2005-4499

JSON object: View

cve-icon Redhat Information

No data.