SB2016100524 - Security restrictions bypass in Cisco MDS 9000 Series Multilayer Switches 



SB2016100524 - Security restrictions bypass in Cisco MDS 9000 Series Multilayer Switches

Published: October 5, 2016 Updated: April 5, 2018

Security Bulletin ID SB2016100524
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security restrictions bypass (CVE-ID: CVE-2015-0721)

The vulnerability allows a remote authenticated user to bypass authentication, authorization, and accounting (AAA) limitations.
The weakness exists due to incorrect handling of parameters passed during negotiation of an SSH connection. Attackers will manage to pass a malicious value as a part of login procedure that allows to bypass AAA restrictions and execute arbitrary commands.
Successful exploitation of the vulnerability results in AAA bypass and access to the vulnerable system.

Remediation

Install update from vendor's website.