CVE-2005-1058: High severity Cisco IOS vulnerability
Cisco IOS 12.2T, 12.3 and 12.3T, when processing an ISAKMP profile that specifies XAUTH authentication after Phase 1 negotiation, may not process certain attributes in the ISAKMP profile that specifies XAUTH, which allows remote attackers to bypass XAUTH and move to Phase 2 negotiations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1058?
CVE-2005-1058 has a medium severity rating due to the potential for remote attackers to bypass authentication.
How do I fix CVE-2005-1058?
To fix CVE-2005-1058, upgrade to a fixed version of Cisco IOS that does not have this vulnerability.
What systems are affected by CVE-2005-1058?
CVE-2005-1058 affects Cisco IOS versions 12.2T, 12.3, and 12.3T.
What type of attack does CVE-2005-1058 allow?
CVE-2005-1058 allows remote attackers to bypass XAUTH authentication and move directly to Phase 2 negotiations.
Is CVE-2005-1058 exploitable over the internet?
Yes, CVE-2005-1058 can be exploited remotely, potentially allowing attackers to exploit vulnerable devices from anywhere.