Vulnerability Description
The default configuration of the RADIUS authentication feature on the Cisco Network Admission Control (NAC) Guest Server with software before 2.0.3 allows remote attackers to bypass intended access restrictions and obtain network connectivity via unspecified vectors, aka Bug ID CSCtj66922.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Nac Guest Server | All versions |
| Cisco | Nac Guest Server Software | <= 2.0.2 |
Related Weaknesses (CWE)
References
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b74114.s
- http://www.securitytracker.com/id?1025272
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b74114.s
- http://www.securitytracker.com/id?1025272
FAQ
What is CVE-2011-0963?
CVE-2011-0963 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The default configuration of the RADIUS authentication feature on the Cisco Network Admission Control (NAC) Guest Server with software before 2.0.3 allows remote attackers to bypass intended access re...
How severe is CVE-2011-0963?
CVE-2011-0963 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-0963?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Nac Guest Server, Cisco Nac Guest Server Software.