PT-1999-1748 · 3Com · 3Com Superstack Ii Hub
Publicado
1999-08-30
·
Atualizado
2016-10-18
·
CVE-1999-1513
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
3Com SuperStack II hub version 2.10
Description:
The Management information base (MIB) for the 3Com SuperStack II hub contains an object identifier (.1.3.6.1.4.1.43.10.4.2) that is accessible by a read-only community string. This object identifier lists the entire table of community strings, which could allow attackers to conduct unauthorized activities.
Recommendations:
For version 2.10, restrict access to the object identifier
.1.3.6.1.4.1.43.10.4.2 to prevent unauthorized disclosure of community strings. Consider changing the read-only community string to a more secure value to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
3Com Superstack Ii Hub