GPU VulnDB

Database/Control plane, storage & DevOps

Cisco IOS XE MACsec Key Agreement (MKA over EAP-TLS): TENANT ISOLATION: a logic error in MKA over EAP-TLS lets

CVE-2018-15372Control plane, storage & DevOpscurated

Impact

TENANT ISOLATION: a logic error in MKA over EAP-TLS lets an unauthenticated adjacent attacker bypass authentication and pass traffic through a Layer 3 interface. MACsec here is doing double duty as link encryption and as port admission control, and both fail — an unauthenticated device on the wire gets its traffic forwarded as though it had authenticated.

Who can reach it

Unauthenticated attacker with adjacent (same-link) access to an interface configured for MKA with EAP-TLS.

What to do

Software upgrade plus device reload. Do not treat MACsec/MKA as your only port-admission control — pair it with per-port VLAN pinning and MAC allowlisting, which are live config changes that keep an unauthenticated device from reaching anything useful even when the MKA check fails.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.