Rapid7 Vulnerability & Exploit Database

Cisco IOS: CVE-2018-0484: Cisco IOS and IOS XE Software Secure Shell Connection on VRF Vulnerability

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

Cisco IOS: CVE-2018-0484: Cisco IOS and IOS XE Software Secure Shell Connection on VRF Vulnerability

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:N/I:P/A:N)
Published
01/10/2019
Created
03/19/2019
Added
01/10/2019
Modified
01/05/2024

Description

A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a virtual routing and forwarding (VRF) instance despite the absence of the vrf-also keyword in the access-class configuration. The vulnerability is due to a missing check in the SSH server. An attacker could use this vulnerability to open an SSH connection to an affected Cisco IOS or IOS XE device with a source address belonging to a VRF instance. Once connected, the attacker would still need to provide valid credentials to access the device.

Solution(s)

  • cisco-ios-upgrade-latest

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;