-
A vulnerability (bug ID CSCdj74723) in AAA authentication processing on Cisco IOS versions 11.3(1.2) and 11.3(1.2)T may allow users to get access for which they are not intended to be authorized. This affects only the 11.3(1.2) and 11.3(1.2)T interim releases. It does not affect any non-interim, production Cisco IOS software release.
The bug that creates this vulnerability may also result in access being denied to legitimate users, or in system crashes. If you are a registered CCO user and you have logged in, you can view bug details.
View CSCdj74723 ( registered customers only)
The complete text of this advisory will be located at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-19980122-aaapair
-
Vulnerable Products
All systems running Cisco IOS Software version 11.3(1.2) or 11.3(1.2)T, and which use TACACS+, RADIUS, or other AAA services for authorization, are affected by this vulnerability. If your configuration includes any command beginning with "aaa authorization", then you are vulnerable. Systems using AAA strictly for login authentication, as opposed to service authorization, and systems using local authentication, are unaffected.
We believe that the most commonly affected configurations will be those using TACACS+ or RADIUS servers.
Systems running engineering special releases containing the fix for bug ID CSCdi51915 may also be affected. If you are a registered CCO user and you have logged in, you can view bug details.
View CSCdi51915 ( registered customers only)
Products Confirmed Not Vulnerable
No other Cisco products are currently known to be affected by these vulnerabilities.
-
This vulnerability (Bug ID CSCdj74723) was introduced by the fix for Bug ID CSCdi51915, which was integrated in Cisco IOS versions 11.3(1.2) and 11.3(1.2)T. It has been fixed for 11.3(1.3) and 11.3(1.3)T. Only these interim releases are affected; CSCdj74723 is not in any regular, released Cisco IOS software image.
Cisco's product security incident response team does not know of any engineering specials that are vulnerable, but, because such specials may be released on an informal basis, it is impossible to determine with absolute certainty whether or not such images exist. Cisco personnel who have been involved in the issuance of specials to customers since January 8, 1998, and customers who have received such specials, are advised to check to make sure that the fix for CSCdi51915 is not in their specials. If that fix is there, the fix for CSCdj74723 must be added to protect against this vulnerability.
-
There is no configuration workaround for this vulnerability, short of completely disabling AAA authorization.
-
When considering software upgrades, also consult http://www.cisco.com/go/psirt and any subsequent advisories to determine exposure and a complete upgrade solution.
In all cases, customers should exercise caution to be certain the devices to be upgraded contain sufficient memory and that current hardware and software configurations will continue to be supported properly by the new release. If the information is not clear, contact the Cisco Technical Assistance Center ("TAC") or your contracted maintenance provider for assistance.
-
Cisco has had no known reports of malicious exploitation of this vulnerability.
Cisco knows of no public announcements of the existence of this vulnerability before the date of this notice.
-
To learn about Cisco security vulnerability disclosure policies and publications, see the Security Vulnerability Policy. This document also contains instructions for obtaining fixed software and receiving security vulnerability information from Cisco.
-
THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.
A stand-alone copy or paraphrase of the text of this document that omits the distribution URL is an uncontrolled copy, and may lack important information or contain factual errors. The information in this document is intended for end-users of Cisco products.