Vulnerability Name: | CVE-2011-0963 (CCN-66470) | ||||||||
Assigned: | 2011-03-30 | ||||||||
Published: | 2011-03-30 | ||||||||
Updated: | 2016-12-07 | ||||||||
Summary: | The default configuration of the RADIUS authentication feature on the Cisco Network Admission Control (NAC) Guest Server with software before 2.0.3 allows remote attackers to bypass intended access restrictions and obtain network connectivity via unspecified vectors, aka Bug ID CSCtj66922. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-0963 Source: CCN Type: SA43925 Cisco NAC Guest Server RADIUS Authentication Bypass Security Issue Source: CCN Type: cisco-sa-20110330-nac Cisco Network Access Control Guest Server System Software Authentication Bypass Vulnerability Source: CISCO Type: UNKNOWN 20110330 Cisco Network Admission Control Guest Server System Software Authentication Bypass Vulnerability Source: CCN Type: OSVDB ID: 72608 Cisco Network Admission Control (NAC) Guest Server RADIUS Unspecified Authentication Bypass Source: CCN Type: BID-47092 Cisco Network Access Control (NAC) Guest Server RADIUS Authentication Bypass Vulnerability Source: SECTRACK Type: UNKNOWN 1025272 Source: XF Type: UNKNOWN cisco-nac-radius-security-bypass(66470) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |