Blog | G5 Cyber Security

Cisco fixes critical authentication bypass bug with public exploit

Cisco has fixed an almost maximum severity authentication bypass vulnerability with public proof-of-concept (PoC) exploit code. The security flaw (tracked as CVE-2021-34746) was found in the TACACS+ authentication, authorization, and accounting (AAA) of Cisco’s Enterprise NFV Infrastructure Software. The vulnerability is caused by incomplete validation of user-supplied input passed to an authentication script during the sign-in process which allows unauthenticated, remote attackers to log in as an administrator.”]

Source: https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-authentication-bypass-bug-with-public-exploit/

Exit mobile version