PT-2010-3245 · Cisco · Cisco Industrial Ethernet 3000+1

Michael Orlando

·

Publicado

2010-07-07

·

Atualizado

2017-08-17

·

CVE-2010-1574

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Industrial Ethernet 3000 series switches versions 12.2(52)SE through 12.2(52)SE1
Description The issue arises from the use of well-known SNMP community names, public for read-only access and private for read-write access, which are hard-coded in the system. This makes it easier for remote attackers to modify the configuration or obtain potentially sensitive information via SNMP requests.
Recommendations For versions 12.2(52)SE and 12.2(52)SE1, perform a Cisco IOS Software upgrade to a version that addresses this issue. As a temporary workaround, consider deploying the mitigation measures outlined in the Workarounds section to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-1574

Produtos afetados

Cisco Ios
Cisco Industrial Ethernet 3000