Release date:
Updated on:
Affected Systems:
Cisco ios xe 03.03.xxSE
Cisco ios xe 03.02.xxSE
Description:
--------------------------------------------------------------------------------
Bugtraq id: 64502
CVE (CAN) ID: CVE-2013-6979
Cisco IOS is an interconnected network operating system used on most Cisco system routers and network switches.
A security vulnerability exists in the vty authentication Implementation of Cisco ios xe Software (03.02.xxSE and 03.03.xxSE). unauthenticated remote attackers can exploit this vulnerability to access affected devices using vty Line Interface permissions, perform unauthorized operations. To exploit this vulnerability, the attacker's source address must be the 192.168.x.2 subnet and communicate with the Cisco ios xe device.
<* Source: Cisco
Link: http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6979
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (CVE-2013-6979) and patches for this:
Cisco ios xe Software Telnet Authentication Bypass Vulnerability CVE-2013-6979
Link: http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6979