SB2016100524 - Security restrictions bypass in Cisco MDS 9000 Series Multilayer Switches
Published: October 5, 2016 Updated: April 5, 2018
Security Bulletin ID
SB2016100524
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security restrictions bypass (CVE-ID: CVE-2015-0721)
The vulnerability allows a remote authenticated user to bypass authentication, authorization, and accounting (AAA) limitations.The weakness exists due to incorrect handling of parameters passed during negotiation of an SSH connection. Attackers will manage to pass a malicious value as a part of login procedure that allows to bypass AAA restrictions and execute arbitrary commands.
Successful exploitation of the vulnerability results in AAA bypass and access to the vulnerable system.
Remediation
Install update from vendor's website.