Vulnerabilities in Cisco IOS Secure Shell Server - Cisco Systems

This script is (C) 2010-2014 Tenable Network Security, Inc.

Synopsis :

The remote device is missing a vendor-supplied security patch.

Description :

Certain release trains of Cisco Internetwork Operating System (IOS),
when configured to use the IOS Secure Shell (SSH) server in combination
with Terminal Access Controller Access Control System Plus (TACACS+) as
a means to perform remote management tasks on IOS devices, may contain
two vulnerabilities that can potentially cause IOS devices to exhaust
resources and reload. Repeated exploitation of these vulnerabilities
can result in a denial of service (DoS) condition. Use of SSH with
other authentication methods like Remote Authentication Dial In User
Service (RADIUS) and the local user database may also be affected.

See also :

Solution :

Apply the relevant patch referenced in Cisco Security Advisory

Risk factor :

High / CVSS Base Score : 7.1
CVSS Temporal Score : 6.7
Public Exploit Available : true

Family: CISCO

Nessus Plugin ID: 48983 (cisco-sa-20050406-sshhttp.nasl)

Bugtraq ID: 13042

CVE ID: CVE-2005-1020

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now