PT-2018-8634 · Cisco · Cisco Policy Suite

Publicado

2018-02-08

·

Atualizado

2020-09-04

·

CVE-2018-0134

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Policy Suite (affected versions not specified)
Description: A vulnerability in the RADIUS authentication module could allow an unauthenticated, remote attacker to determine whether a subscriber username is valid. This occurs because the RADIUS server component returns different authentication failure messages based on the validity of usernames. An attacker could use these messages to determine whether a valid subscriber username has been identified and use this information in subsequent attacks against the system.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Side Channel Attack

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-0134

Produtos afetados

Cisco Policy Suite