security2 publishers
Elttam's two-packet TACACS+ exploit runs code on the servers that approve router logins
Elttam says two packets and an offline crack of weak encryption let attackers run code on TACACS+ servers before login. Only the Shrubbery Networks build has a patch, leaving sites on the archived Facebook fork to migrate or limit who can reach port 49.
Reality
- Evidence42
- Adoption
- Insufficient
- Hype gap+15
- Incentives40
- Confidence45