Medium severity6.5NVD Advisory· Published Mar 28, 2018· Updated Jun 17, 2026
CVE-2018-0163
CVE-2018-0163
Description
A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass the authentication phase on an 802.1x multi-auth port. The vulnerability is due to a logic change error introduced into the code. An attacker could exploit this vulnerability by trying to access an 802.1x multi-auth port after a successful supplicant has authenticated. An exploit could allow the attacker to bypass the 802.1x access controls and obtain access to the network. Cisco Bug IDs: CSCvg69701.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
34cpe:2.3:o:cisco:ios:15.4\(3.0i\)m6:*:*:*:*:*:*:*+ 33 more
- cpe:2.3:o:cisco:ios:15.4\(3.0i\)m6:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.4\(3\)m6:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.4\(3\)m6a:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.4\(3\)m7:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.4\(3\)m7a:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.4\(3\)m8:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.5\(3\)m3:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.5\(3\)m4:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.5\(3\)m4a:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.5\(3\)m4b:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.5\(3\)m4c:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.5\(3\)m5:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.5\(3\)m5a:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.5\(3\)m6:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.5\(3\)m6a:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.6\(1\)t2:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.6\(1\)t3:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.6\(2\)t1:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.6\(2\)t2:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.6\(2\)t3:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.6\(3\)m0a:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.6\(3\)m1:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.6\(3\)m1a:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.6\(3\)m1b:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.6\(3\)m2:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.6\(3\)m2a:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.6\(3\)m3:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.6\(3\)m3a:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.6\(3\)m:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.7\(3\)m0a:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.7\(3\)m1:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.7\(3\)m2:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:15.7\(3\)m:*:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
2- www.securityfocus.com/bid/103571nvdThird Party AdvisoryVDB Entry
- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-dot1xnvdVendor Advisory
News mentions
0No linked articles in our index yet.