CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer
image ATP: Cisco Flaw Leaves Switches Vulnerable image
Security Hole
By Dennis Fisher
April 24, 2003

Cisco Systems Inc. on Thursday warned its customers about a serious security vulnerability in the software that controls several of its popular switches. The flaw enables attackers to bypass the password authentication and get control over a vulnerable switch.

The vulnerability is found in the Catalyst OS software version 7.5(1), which runs on Catalyst 4000, 6000 and 6500 series switches. The problem does not affect the Cisco IOS software.

To exploit this flaw, an attacker would need to be able to get command-line access to an affected switch. This could be accomplished in one of several ways, including through the switch's administrative console, Telnet or SSH.

Once at the command line, the attacker need only have a valid username to gain access to the "enable" mode on the switch. As long as local user authentication is enabled, no password is required. Enable mode would allow the attacker to make configuration changes to the switch.

www.eweek.com


Source: eWEEK
Patches and advisory: Cisco

Posted on Thursday, 24 April 2003 @ 15:47:59 UTC by cj (1106 reads)
[ Trackback ]
image

"ATP: Cisco Flaw Leaves Switches Vulnerable" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· HotScripts
· W3 Consortium
· More about Security Hole
· News by cj


Most read story about Security Hole:
Windows Media Player, Spyware and Trojan

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer