CVE-2005-1020
Last modified
CVE-2005-1020 is a vulnerability of currently unknown severity. Secure Shell (SSH) 2 in Cisco IOS 12.0 through 12.3 allows remote attackers to cause a denial of service (device reload) (1) via a username that contains a domain name when using a TACACS+ server to authenticate, (2) when a new SSH session is in the login phase and a currently logged in user issues a send command, or (3) when IOS is logging messages and an SSH session is terminated while the server is sending data.. EPSS estimates a 1.73% chance of exploitation in the next 30 days.
Description
Secure Shell (SSH) 2 in Cisco IOS 12.0 through 12.3 allows remote attackers to cause a denial of service (device reload) (1) via a username that contains a domain name when using a TACACS+ server to authenticate, (2) when a new SSH session is in the login phase and a currently logged in user issues a send command, or (3) when IOS is logging messages and an SSH session is terminated while the server is sending data.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios | 12.0 |
| Cisco | Ios | 12.0\(23\)s4 |
| Cisco | Ios | 12.0\(23\)s5 |
| Cisco | Ios | 12.0\(24\)s1 |
| Cisco | Ios | 12.0\(24\)s4 |
| Cisco | Ios | 12.0\(24\)s5 |
| Cisco | Ios | 12.0\(24.2\)s |
| Cisco | Ios | 12.0\(26\)s1 |
| Cisco | Ios | 12.0\(27\)s |
| Cisco | Ios | 12.0\(27\)sv |
| Cisco | Ios | 12.0\(27\)sv1 |
| Cisco | Ios | 12.0da |
| Cisco | Ios | 12.0db |
| Cisco | Ios | 12.0dc |
| Cisco | Ios | 12.0s |
| Cisco | Ios | 12.0sc |
| Cisco | Ios | 12.0sl |
| Cisco | Ios | 12.0sp |
| Cisco | Ios | 12.0st |
| Cisco | Ios | 12.0sv |
| Cisco | Ios | 12.0sx |
| Cisco | Ios | 12.0sy |
| Cisco | Ios | 12.0sz |
| Cisco | Ios | 12.0t |
| Cisco | Ios | 12.0w5 |
| Cisco | Ios | 12.0wc |
| Cisco | Ios | 12.0wt |
| Cisco | Ios | 12.0wx |
| Cisco | Ios | 12.0xa |
| Cisco | Ios | 12.0xb |
| Cisco | Ios | 12.0xc |
| Cisco | Ios | 12.0xd |
| Cisco | Ios | 12.0xe |
| Cisco | Ios | 12.0xf |
| Cisco | Ios | 12.0xg |
| Cisco | Ios | 12.0xh |
| Cisco | Ios | 12.0xi |
| Cisco | Ios | 12.0xj |
| Cisco | Ios | 12.0xk |
| Cisco | Ios | 12.0xl |
| Cisco | Ios | 12.0xm |
| Cisco | Ios | 12.0xn |
| Cisco | Ios | 12.0xp |
| Cisco | Ios | 12.0xq |
| Cisco | Ios | 12.0xr |
| Cisco | Ios | 12.0xs |
| Cisco | Ios | 12.0xt |
| Cisco | Ios | 12.0xu |
| Cisco | Ios | 12.0xv |
| Cisco | Ios | 12.0xw |
Showing 50 of 337 affected configurations. See NVD for the full list.
References
- http://secunia.com/advisories/14854Patch, Vendor Advisory
- http://www.securitytracker.com/alerts/2005/Apr/1013655.htmlVendor Advisory
- http://secunia.com/advisories/14854Patch, Vendor Advisory
- http://www.securitytracker.com/alerts/2005/Apr/1013655.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-1020?
How severe is CVE-2005-1020?
How do I fix CVE-2005-1020?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-1014Buffer overflow in the IMAP service for MailEnable Enterpris…
- CVE-2005-1015Buffer overflow in MailEnable Imapd (MEIMAP.exe) allows remo…
- CVE-2005-1016Cross-site scripting (XSS) vulnerability in links_add_form.a…
- CVE-2005-1017SQL injection vulnerability in the Update_Events function in…
- CVE-2005-1018Buffer overflow in the UniversalAgent for Computer Associate…
- CVE-2005-1019Buffer overflow in the getConfig function in Aeon 0.2a and e…
- CVE-2005-1021Memory leak in Secure Shell (SSH) in Cisco IOS 12.0 through …
- CVE-2005-1022ColdFusion 6.1 Updater 1 places Java .class files under the …
- CVE-2005-1023Multiple cross-site scripting (XSS) vulnerabilities in PHP-N…
- CVE-2005-1024modules.php in PHP-Nuke 6.x to 7.6 allows remote attackers t…
- CVE-2005-1025The FTP server in AS/400 4.3, when running in IFS mode, allo…
- CVE-2005-1026Multiple SQL injection vulnerabilities in SnailSource phpBB …
Are you affected by CVE-2005-1020?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
