[VPN] Cisco Security Advisory - Vuln in XAUTH implementation
tbird at precision-guesswork.com
Wed Apr 6 13:21:38 EDT 2005
>From the advisory:
Cisco Internetwork Operating System (IOS) Software release trains 12.2T,
12.3 and 12.3T may contain vulnerabilities in processing certain Internet
Key Exchange (IKE) Xauth messages when configured to be an Easy VPN Server.
Successful exploitation of these vulnerabilities may permit an unauthorized
user to complete authentication and potentially access network resources.
This advisory will be posted to
Cisco has made free software available to address this vulnerability for
More information about the VPN