|
Cisco IOS Unauthorized Security Association Establishment Vulnerability
Cisco IOS is prone to an issue related to XAUTH and ISAKMP profiles that may allow a malicious VPN client to gain unauthorized access to a VPN. The vulnerability occurs in a case where attributes in an ISAKMP profile that have been assigned to remote peer are not processed. This will present a window of opportunity for the remote client to initiate Phase 2 IKE negotiation and cause an unauthorized IPSec SA (Security Association) to be established. It is noted that the vulnerability only affects those ISAKMP profiles that are matched by pre-configured certificate maps. |
|
|
Privacy Statement |