Vulnerability Name: | CVE-2011-0935 (CCN-66838) | ||||||||
Assigned: | 2010-12-28 | ||||||||
Published: | 2010-12-28 | ||||||||
Updated: | 2011-04-21 | ||||||||
Summary: | The PKI functionality in Cisco IOS 15.0 and 15.1 does not prevent permanent caching of certain public keys, which allows remote attackers to bypass authentication and have unspecified other impact by leveraging an IKE peer relationship in which a key was previously valid but later revoked, aka Bug ID CSCth82164, a different vulnerability than CVE-2010-4685. CVSS score derived from: http://www.cisco.com/en/US/docs/ios/15_1s/release/notes/15_1s_caveats_15_1_2s.html | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-310 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-0935 Source: CCN Type: SA44363 Cisco IOS OCSP Revoked Certificate Security Issue Source: CCN Type: Cisco Web site Release Notes for Cisco 800 Series Routers with Cisco IOS Release 15.0(1)XA Source: CONFIRM Type: UNKNOWN http://www.cisco.com/en/US/docs/ios/15_1/release/notes/151-2TCAVS.html Source: CONFIRM Type: UNKNOWN http://www.cisco.com/en/US/docs/ios/15_1s/release/notes/15_1s_caveats_15_1_1s.html Source: BID Type: UNKNOWN 47407 Source: CCN Type: BID-47407 Cisco IOS PKI Functionality Security Bypass Vulnerability Source: XF Type: UNKNOWN ciscoios-pki-sec-bypass(66838) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |