CVE-2015-0607: Cisco IOS

Medium severity, CVSS 4.3. EPSS: 2% chance of exploitation in the next 30 days.

The Authentication Proxy feature in Cisco IOS does not properly handle invalid AAA return codes from RADIUS and TACACS+ servers, which allows remote attackers to bypass authentication in opportunistic circumstances via a connection attempt that triggers an invalid code, as demonstrated by a connection attempt with a blank password, aka Bug IDs CSCuo09400 and CSCun16016.

Affected products

  • Cisco IOS: version 15.4(1)t only; version 15.4(1)t1 only; version 15.4(1)t2 only; version 15.4(1)t3 only; version 15.4(1)t4 only; version 15.4(2)t only; …

Published 2015-03-06. Last modified 2026-06-17.