Cisco LEAP密码泄露漏洞

Cisco LEAP密码泄露漏洞

漏洞ID 1107501 漏洞类型 设计错误
发布时间 2003-10-03 更新时间 2005-10-20
图片[1]-Cisco LEAP密码泄露漏洞-安全小百科CVE编号 CVE-2003-1096
图片[2]-Cisco LEAP密码泄露漏洞-安全小百科CNNVD-ID CNNVD-200312-100
漏洞平台 Hardware CVSS评分 10.0
|漏洞来源
https://www.exploit-db.com/exploits/23212
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200312-100
|漏洞详情
CiscoLEAPchallenge/response认证机制以一种易受字典式攻击的方法使用密码。远程攻击者更容易借助强力密码猜测攻击提升特权。
|漏洞EXP
source: http://www.securityfocus.com/bid/8755/info

It has been reported that Cisco LEAP (Lightweight Extensible
Authentication Protocol) is prone to a password disclosure weakness that may allow a remote user to steal user passwords. The issue may be exploited out by brute forcing user passwords using dictionary attacks.

Successful exploitation of this weakness may allow a remote attacker to steal authentication information, potentially allowing for unauthorized network access. 

https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/bin-sploits/23212.tar.bz2
|参考资料

来源:US-CERTVulnerabilityNote:VU#473108
名称:VU#473108
链接:http://www.kb.cert.org/vuls/id/473108
来源:XF
名称:cisco-leap-dictionary(12804)
链接:http://xforce.iss.net/xforce/xfdb/12804
来源:BID
名称:8755
链接:http://www.securityfocus.com/bid/8755
来源:BUGTRAQ
名称:20031006WeaknessesinLEAPChallenge/Response
链接:http://www.securityfocus.com/archive/1/340365
来源:BUGTRAQ
名称:20031003DictionaryattackagainstCisco’sLEAP,WirelessLANsvulnerable
链接:http://www.securityfocus.com/archive/1/340119
来源:CISCO
名称:20030803DictionaryAttackonCiscoLEAPVulnerability
链接:http://www.cisco.com/warp/public/707/cisco-sn-20030802-leap.shtml
来源:BUGTRAQ
名称:20040407ReleaseofCiscoAttacktoolAsleap
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=108135227731965&w;=2
来源:OSVDB
名称:15209
链接:http://www.osvdb.org/15209

相关推荐: Epic Games Unreal Engine Multiple Players Denial Of Service Vulnerability

Epic Games Unreal Engine Multiple Players Denial Of Service Vulnerability 漏洞ID 1100850 漏洞类型 Design Error 发布时间 2003-02-05 更新时间 2003…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享