A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a virtual routing and forwarding (VRF) instance despite the absence of the vrf-also keyword in the access-class configuration. The vulnerability is due to a missing check in the SSH server. An attacker could use this vulnerability to open an SSH connection to an affected Cisco IOS or IOS XE device with a source address belonging to a VRF instance. Once connected, the attacker would still need to provide valid credentials to access the device.
Metrics
Affected Vendors & Products
References
History
Tue, 19 Nov 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: cisco
Published: 2019-01-10T18:00:00Z
Updated: 2024-11-19T19:18:45.475Z
Reserved: 2017-11-27T00:00:00
Link: CVE-2018-0484
Vulnrichment
Updated: 2024-08-05T03:28:11.002Z
NVD
Status : Modified
Published: 2019-01-10T18:29:00.377
Modified: 2024-11-21T03:38:19.630
Link: CVE-2018-0484
Redhat
No data.