>> Cisco IOS IKE Xauth Authentication Bypass Vulnerabilities
Title : Cisco IOS IKE Xauth Authentication Bypass Vulnerabilities VUPEN ID : VUPEN/ADV-2005-0321 CVE ID : GENERIC-MAP-NOMATCH CWE ID : CWE-
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-04-06
Technical Description
Two vulnerabilities were identified in Cisco IOS, which may be exploited by remote attackers to gain unauthorized access to the network resources.
- The first flaw resides in the Easy VPN Server XAUTH feature which fails to handle certain malformed packets (port 500/udp), which may permit an unauthorized user to complete Xauth authentication and thereby gain access to network resources.
- The second vulnerability exists where the ISAKMP profile is assigned but the attributes that are configured in the ISAKMP profile are not processed. This can result in a situtation where both the VPN client and VPN server are expecting to hear something from the other end of the connection. Normally this deadlock will be broken by idle timers tearing down the SA, but it is possible for a malicious client to propose Phase 2 negotiation during this time which may allow for the IPSec SA to be fully established.