漏洞信息详情
Cisco LEAP密码泄露漏洞
- CNNVD编号:CNNVD-200312-100
- 危害等级: 超危
- CVE编号:
CVE-2003-1096
- 漏洞类型:
设计错误
- 发布时间:
2003-12-31
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
cisco - 漏洞来源:
The disclosure of … -
漏洞简介
Cisco LEAP challenge/response认证机制以一种易受字典式攻击的方法使用密码。远程攻击者更容易借助强力密码猜测攻击提升特权。
漏洞公告
Cisco has announced the EAP-FAST protocol as a secure replacement for LEAP. Users are advised to migrate to this or other protocols such as PEAP or EAP-TLS. More information can be found in the referenced vendor advisory (Dictionary Attack on Cisco LEAP Vulnerability).
参考网址
来源:US-CERT Vulnerability Note: VU#473108
名称: VU#473108
链接:http://www.kb.cert.org/vuls/id/473108
来源: XF
名称: cisco-leap-dictionary(12804)
链接:http://xforce.iss.net/xforce/xfdb/12804
来源: BID
名称: 8755
链接:http://www.securityfocus.com/bid/8755
来源: BUGTRAQ
名称: 20031006 Weaknesses in LEAP Challenge/Response
链接:http://www.securityfocus.com/archive/1/340365
来源: BUGTRAQ
名称: 20031003 Dictionary attack against Cisco’s LEAP, Wireless LANs vulnerable
链接:http://www.securityfocus.com/archive/1/340119
来源: CISCO
名称: 20030803 Dictionary Attack on Cisco LEAP Vulnerability
链接:http://www.cisco.com/warp/public/707/cisco-sn-20030802-leap.shtml
来源: BUGTRAQ
名称: 20040407 Release of Cisco Attack tool Asleap
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=108135227731965&w=2
来源: OSVDB
名称: 15209
链接:http://www.osvdb.org/15209