296,747
Total vulnerabilities in the database
Cisco IOS 12.2 and earlier generates a "% Login invalid" message instead of prompting for a password when an invalid username is provided, which allows remote attackers to identify valid usernames on the system and conduct brute force password guessing, as reported for the Aironet Bridge.
| Software | From | Fixed in |
|---|---|---|
| cisco / ios | 12.2(14.5)t | 12.2(14.5)t.x |
| cisco / ios | 12.0(24.2)s | 12.0(24.2)s.x |
| cisco / ios | 12.0(24)s1 | 12.0(24)s1.x |
| cisco / ios | 12.2(15)zn | 12.2(15)zn.x |
| cisco / ios | 12.2(11)ja1 | 12.2(11)ja1.x |
| cisco / ios | 12.2(16)b | 12.2(16)b.x |
| cisco / ios | 12.2(15.1)s | 12.2(15.1)s.x |
| cisco / ios | 12.2(14.5) | 12.2(14.5).x |
| cisco / ios | 12.2(16.1)b | 12.2(16.1)b.x |