PT-2018-8634 · Cisco · Cisco Policy Suite

Published

2018-02-08

·

Updated

2020-09-04

·

CVE-2018-0134

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Policy Suite (affected versions not specified)
Description: A vulnerability in the RADIUS authentication module could allow an unauthenticated, remote attacker to determine whether a subscriber username is valid. This occurs because the RADIUS server component returns different authentication failure messages based on the validity of usernames. An attacker could use these messages to determine whether a valid subscriber username has been identified and use this information in subsequent attacks against the system.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-0134

Affected Products

Cisco Policy Suite