Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Cisco IOS Unauthorized Security Association Establishment Vulnerability

Cisco IOS is prone to an issue related to XAUTH and ISAKMP profiles that may allow a malicious VPN client to gain unauthorized access to a VPN.

The vulnerability occurs in a case where attributes in an ISAKMP profile that have been assigned to remote peer are not processed. This will present a window of opportunity for the remote client to initiate Phase 2 IKE negotiation and cause an unauthorized IPSec SA (Security Association) to be established.

It is noted that the vulnerability only affects those ISAKMP profiles that are matched by pre-configured certificate maps.







 

Privacy Statement
Copyright 2008, SecurityFocus