PT-2013-5603 · Cisco · Cisco Ios

Publicado

2013-10-25

·

Atualizado

2013-10-25

·

CVE-2013-5522

CVSS v2.0

6.8

Média

VetorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS on Catalyst 3750X switches (affected versions not specified)
Description A vulnerability exists due to default Service Module credentials, allowing local users to gain privileges via a Service Module login. This issue makes it easier for an authenticated, local attacker to gain root access to the kernel running on the Cisco Service Module by logging in using the default credentials. An exploit could allow the attacker to take complete control of the operating system running on the service module. The vulnerability can be exploited by an attacker with local access to a targeted device, which may reside on trusted, internal networks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-5522

Produtos afetados

Cisco Ios