Title : Cisco IOS Firewall Authentication Proxy Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2005-1669 CVE ID : CVE-2005-2841 CWE ID : CWE-
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-09-07
Technical Description
A vulnerability has been identified in Cisco IOS, which could be exploited by remote attackers to execute arbitrary commands or cause a denial of service. This flaw is due to a buffer overflow error in the Firewall Authentication Proxy for FTP and Telnet Sessions feature that does not properly handle specially crafted authentication credentials, which could be exploited by remote unauthenticated attackers to compromise a vulnerable device via a specially crafted authentication request.
Note : Devices that do not support, or are not configured for Firewall Authentication Proxy for FTP and/or Telnet Services are not affected.