← Back

CVE-2013-6979

nvd nist
Published: Dec 23, 2013Modified: Apr 29, 2026

JSON object

Loading...
5.4
Vector
AV:N/AC:H/Au:N/C:C/I:N/A:N
Exploitability: 4.9 / Impact: 6.9
Source: NVD

Description

The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS internal-network configuration, which allows remote attackers to bypass authentication by leveraging access to a 192.168.x.2 source IP address, aka Bug ID CSCuj90227.

Affected (1)

Products: Cisco: Ios Xe
1 product
Ios Xe
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (10)

Source: psirt@cisco.com
Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.