CVE-2011-0935
The PKI functionality in Cisco IOS 15.0 and 15.1 does not prevent permanent caching of certain public keys, which allows remote attackers to bypass authentication and have unspecified other impact by leveraging an IKE peer relationship in which a key…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.99%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The PKI functionality in Cisco IOS 15.0 and 15.1 does not prevent permanent caching of certain public keys, which allows remote attackers to bypass authentication and have unspecified other impact by leveraging an IKE peer relationship in which a key was previously valid but later revoked, aka Bug ID CSCth82164, a different vulnerability than CVE-2010-4685.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 3.99% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- cisco/ios
- Source
- psirt@cisco.com
References
- http://www.cisco.com/en/US/docs/ios/15_1/release/notes/151-2TCAVS.html
- http://www.cisco.com/en/US/docs/ios/15_1s/release/notes/15_1s_caveats_15_1_1s.html
- http://www.securityfocus.com/bid/47407
- http://www.cisco.com/en/US/docs/ios/15_1/release/notes/151-2TCAVS.html
- http://www.cisco.com/en/US/docs/ios/15_1s/release/notes/15_1s_caveats_15_1_1s.html
- http://www.securityfocus.com/bid/47407
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.