GPU VulnDB

Database/Control plane, storage & DevOps

Cisco IOS XE MACsec Key Agreement (MKA over EAP-TLS): A logic error in MKA over EAP-TLS lets an unauthenticated

CVSS 8.1CVE-2018-15372Control plane, storage & DevOpscurated

Impact

A logic error in MKA over EAP-TLS lets an unauthenticated adjacent attacker bypass authentication and pass traffic through a Layer 3 interface. MACsec here is doing double duty as link encryption and as port admission control, and both fail — an unauthenticated device on the wire gets its traffic forwarded as though it had authenticated.

Who can reach it

Unauthenticated attacker with adjacent (same-link) access to an interface configured for MKA with EAP-TLS.

What to do

Software upgrade plus device reload. Do not treat MACsec/MKA as your only port-admission control — pair it with per-port VLAN pinning and MAC allowlisting, which are live config changes that keep an unauthenticated device from reaching anything useful even when the MKA check fails.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.