Vulnerability Name:

CVE-2003-0512 (CCN-12745)

Assigned:2003-07-28
Published:2003-07-28
Updated:2017-10-11
Summary:Cisco IOS 12.2 and earlier generates a "% Login invalid" message instead of prompting for a password when an invalid username is provided, which allows remote attackers to identify valid usernames on the system and conduct brute force password guessing, as reported for the Aironet Bridge.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-310
Vulnerability Consequences:Obtain Information
References:Source: VULNWATCH
Type: Vendor Advisory
20030728 Cisco Aironet AP1100 Valid Account Disclosure Vulnerability

Source: MITRE
Type: CNA
CVE-2003-0512

Source: CCN
Type: Cisco Security Document ID: 44161
Enumerating Locally Defined Users in Cisco IOS

Source: CISCO
Type: UNKNOWN
20030724 Enumerating Locally Defined Users in Cisco IOS

Source: CCN
Type: US-CERT VU#886796
Cisco Aironet AP1100 fails to provide universal login error messages thereby disclosing validity of user account

Source: CERT-VN
Type: US Government Resource
VU#886796

Source: CCN
Type: OSVDB ID: 2341
Cisco IOS Valid Username Enumeration

Source: CCN
Type: BID-8292
Cisco Aironet Telnet Service User Account Enumeration Weakness

Source: CCN
Type: VIGILANTe Security Watch Advisory 2003002
Cisco Aironet AP1100 Valid Account Disclosure Vulnerability

Source: MISC
Type: UNKNOWN
http://www.vigilante.com/inetsecurity/advisories/VIGILANTE-2003002.htm

Source: XF
Type: UNKNOWN
cisco-ios-account-bruteforce(12745)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:5824

Vulnerable Configuration:Configuration 1:
  • cpe:/o:cisco:ios:12.0(24)s1:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.0(24.2)s:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2(11)ja1:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2(14.5):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2(14.5)t:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2(15)zn:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2(15.1)s:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2(16)b:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2(16.1)b:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:cisco:ios:12.0(24)s1:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.0(24.2)s:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2(11)ja1:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2(14.5):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2(14.5)t:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2(15)zn:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2(15.1)s:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2(16)b:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2(16.1)b:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:5824
    V
    Cisco IOS User Enumeration via Error Messages
    2008-09-08
    BACK
    cisco ios 12.0(24)s1
    cisco ios 12.0(24.2)s
    cisco ios 12.2(11)ja1
    cisco ios 12.2(14.5)
    cisco ios 12.2(14.5)t
    cisco ios 12.2(15)zn
    cisco ios 12.2(15.1)s
    cisco ios 12.2(16)b
    cisco ios 12.2(16.1)b
    cisco ios 12.0(24)s1
    cisco ios 12.0(24.2)s
    cisco ios 12.2(11)ja1
    cisco ios 12.2(14.5)
    cisco ios 12.2(14.5)t
    cisco ios 12.2(15)zn
    cisco ios 12.2(15.1)s
    cisco ios 12.2(16)b
    cisco ios 12.2(16.1)b