PT-2001-2344 · Cisco · Cisco Ubr900 Series Routers
Published
2001-12-30
·
Updated
2008-09-10
·
CVE-2001-1210
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco ubr900 series routers (affected versions not specified)
Description
The issue concerns Cisco ubr900 series routers that conform to the Data-over-Cable Service Interface Specifications (DOCSIS) standard. These routers ship without SNMP access restrictions, allowing remote attackers to read and write information to the MIB using arbitrary community strings.
Recommendations
For Cisco ubr900 series routers, consider implementing SNMP access restrictions to prevent unauthorized access to the MIB. As a temporary workaround, restrict access to the SNMP service until a more permanent solution is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ubr900 Series Routers