Vulnerability CVE-2010-1574


Published: 2010-07-08   Modified: 2012-02-13

Description:
IOS 12.2(52)SE and 12.2(52)SE1 on Cisco Industrial Ethernet (IE) 3000 series switches has (1) a community name of public for RO access and (2) a community name of private for RW access, which makes it easier for remote attackers to modify the configuration or obtain potentially sensitive information via SNMP requests, aka Bug ID CSCtf25589.

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Cisco -> Industrial ethernet 3000 
Cisco -> IOS 

 References:
http://www.kb.cert.org/vuls/id/732671
http://xforce.iss.net/xforce/xfdb/60145
http://www.vupen.com/english/advisories/2010/1754
http://www.securityfocus.com/bid/41436
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b3891f.shtml
http://securitytracker.com/id?1024173
http://secunia.com/advisories/40407
http://osvdb.org/66120

Copyright 2024, cxsecurity.com

 

Back to Top