CVE-2013-6979: Medium severity Cisco IOS XE vulnerability
Published Dec 23, 2013
·Updated
The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS internal-network configuration, which allows remote attackers to bypass authentication by leveraging access to a 192.168.x.2 source IP address, aka Bug ID CSCuj90227.
Affected Software
1 affected component
Cisco IOS XE
Event History
Dec 23, 2013
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6979?
CVE-2013-6979 has a high severity level due to its potential for remote attackers to bypass authentication.
2
How do I fix CVE-2013-6979?
To fix CVE-2013-6979, update your Cisco IOS XE to a version that addresses this vulnerability.
3
Who is affected by CVE-2013-6979?
CVE-2013-6979 affects devices running Cisco IOS XE versions 03.02.xxSE and 03.03.xxSE.
4
What type of vulnerability is CVE-2013-6979?
CVE-2013-6979 is an authentication bypass vulnerability.
5
Can an attacker exploit CVE-2013-6979 from any remote location?
No, an attacker needs to leverage access to a specific internal IP address, 192.168.x.2, to exploit CVE-2013-6979.