PT-2003-1291 · Cisco+2 · Cisco Ons15454+3
Published
2003-03-18
·
Updated
2018-10-30
·
CVE-2002-1558
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco ONS15454 and ONS15327 versions prior to 3.4
Description
The issue allows remote attackers to gain privileges by connecting to an account via Telnet, as there is an account for the VxWorks Operating System in the TCC, TCC+, and XTC that cannot be changed or disabled.
Recommendations
For versions prior to 3.4, consider restricting access to the Telnet service to minimize the risk of exploitation. As a temporary workaround, limit connections to the affected account until a fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ons15327
Cisco Ons15454
Telnet
Vxworks Operating System