CVE-2015-0607: Cisco IOS
Medium severity, CVSS 4.3. EPSS: 2% chance of exploitation in the next 30 days.
The Authentication Proxy feature in Cisco IOS does not properly handle invalid AAA return codes from RADIUS and TACACS+ servers, which allows remote attackers to bypass authentication in opportunistic circumstances via a connection attempt that triggers an invalid code, as demonstrated by a connection attempt with a blank password, aka Bug IDs CSCuo09400 and CSCun16016.
Affected products
- Cisco IOS: version 15.4(1)t only; version 15.4(1)t1 only; version 15.4(1)t2 only; version 15.4(1)t3 only; version 15.4(1)t4 only; version 15.4(2)t only; …
Published 2015-03-06. Last modified 2026-06-17.