>> Cisco IOS Secure Shell Server Denial of Service Vulnerabilities
Title : Cisco IOS Secure Shell Server Denial of Service Vulnerabilities VUPEN ID : VUPEN/ADV-2005-0320 CVE ID : GENERIC-MAP-NOMATCH CWE ID : CWE-
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-04-06
Technical Description
Two vulnerabilities were identified in Cisco IOS, which may be exploited by remote attackers to cause a denial of service.
- The first flaw affects IOS when configured to act as a SSH version 2, and occurs when handling a TACACS+ username containing domain name, which may be exploited to cause a device to reload.
- The second vulnerability consists of a memory leak that happens when an IOS device is configured to authenticate SSH users against a TACACS+ server and the login fails due to an invalid username or password.