Back to search
CVE-2003-0512
Published: Jul 29, 2003
Modified: Aug 8, 2024
PUBLISHED
Description
Cisco IOS 12.2 and earlier generates a "% Login invalid" message instead of prompting for a password when an invalid username is provided, which allows remote attackers to identify valid usernames on the system and conduct brute force password guessing, as reported for the Aironet Bridge.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20030724 Enumerating Locally Defined Users in Cisco IOS
vendor-advisory
x_refsource_CISCO
oval:org.mitre.oval:def:5824
vdb-entry
signature
x_refsource_OVAL
20030728 Cisco Aironet AP1100 Valid Account Disclosure Vulnerability
mailing-list
x_refsource_VULNWATCH
VU#886796
third-party-advisory
x_refsource_CERT-VN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now