PT-2018-8634 · Cisco · Cisco Policy Suite
Published
2018-02-08
·
Updated
2020-09-04
·
CVE-2018-0134
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Cisco Policy Suite (affected versions not specified)
Description:
A vulnerability in the RADIUS authentication module could allow an unauthenticated, remote attacker to determine whether a subscriber username is valid. This occurs because the RADIUS server component returns different authentication failure messages based on the validity of usernames. An attacker could use these messages to determine whether a valid subscriber username has been identified and use this information in subsequent attacks against the system.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Policy Suite