cve/2005/CVE-2005-1058.md

18 lines
775 B
Markdown
Raw Normal View History

2024-07-25 21:25:12 +00:00
### [CVE-2005-1058](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1058)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
Cisco IOS 12.2T, 12.3 and 12.3T, when processing an ISAKMP profile that specifies XAUTH authentication after Phase 1 negotiation, may not process certain attributes in the ISAKMP profile that specifies XAUTH, which allows remote attackers to bypass XAUTH and move to Phase 2 negotiations.
### POC
#### Reference
- http://www.cisco.com/warp/public/707/cisco-sa-20050406-xauth.shtml
#### Github
No PoCs found on GitHub currently.