Executive brief
A security flaw in older Cisco networking hardware allows unauthorized users to bypass authentication when establishing Point-to-Point Protocol (PPP) connections. This could allow an attacker to gain unauthorized access to the network, potentially leading to data interception or further compromise of the corporate infrastructure. The issue affects the Challenge Handshake Authentication Protocol (CHAP) used to verify the identity of remote devices.
Technical details
A vulnerability exists in the implementation of the Challenge Handshake Authentication Protocol (CHAP) within Cisco IOS. The flaw allows a remote attacker to bypass the authentication mechanism required to establish a Point-to-Point Protocol (PPP) connection. By successfully exploiting this issue, an unauthenticated attacker can gain network access that should be restricted to authorized users. The vulnerability is rated with a CVSS v2.0 base score of 7.5, reflecting its impact on confidentiality, integrity, and availability.
Affected products
- Cisco IOS
Timeline
- 1997-10-01: disclosed