Authentication bypass in Policy Suite - CVE-2018-0116
Published: February 8, 2018
Policy Suite
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication on the target system.
The vulnerability is due to incorrect RADIUS user credential validation. An attacker could exploit this vulnerability by attempt to access a Cisco Policy Suite domain configured with RADIUS authentication and be authorized as a subscriber without providing a valid password.