A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass the authentication phase on an 802.1x multi-auth port. The vulnerability is due to a logic change error introduced into the code. An attacker could exploit this vulnerability by trying to access an 802.1x multi-auth port after a successful supplicant has authenticated. An exploit could allow the attacker to bypass the 802.1x access controls and obtain access to the network. Cisco Bug IDs: CSCvg69701.
Attack Vector Adjacent Network
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact None
Integrity Impact High
Availability Impact None
User Interaction None
No CVSS v3.0
Access Vector Adjacent Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact Partial
Availability Impact None
AV:A/AC:L/Au:N/C:N/I:P/A:N
Vendors | Products |
---|---|
Cisco |
|
Rockwellautomation |
|
Configuration 1 [-]
AND |
|
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/103571 | Third Party Advisory VDB Entry |
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-dot1x | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: cisco
Published: 2018-03-28T22:00:00
Updated: 2018-04-03T09:57:01
Reserved: 2017-11-27T00:00:00
Link: CVE-2018-0163
JSON object: View
NVD Information
Status : Analyzed
Published: 2018-03-28T22:29:00.750
Modified: 2021-04-28T22:38:37.293
Link: CVE-2018-0163
JSON object: View
Redhat Information
No data.
CWE