CVE-2003-0512: Medium severity Cisco IOS vulnerability
Cisco IOS 12.2 and earlier generates a "% Login invalid" message instead of prompting for a password when an invalid username is provided, which allows remote attackers to identify valid usernames on the system and conduct brute force password guessing, as reported for the Aironet Bridge.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
An attacker can probe the login service remotely without authentication. Supplying invalid usernames produces a distinct "% Login invalid" response that can be used to identify valid accounts.
What is the practical impact of confirming valid usernames?
Valid username enumeration can make brute-force password guessing more efficient by letting an attacker focus attempts on known accounts. The issue does not itself provide authentication bypass or account access.
Which systems are affected?
The provided information identifies Cisco IOS 12.2 and earlier, with the behavior reported for the Aironet Bridge.