PT-2010-3245 · Cisco · Cisco Industrial Ethernet 3000+1
Michael Orlando
·
Published
2010-07-07
·
Updated
2017-08-17
·
CVE-2010-1574
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Industrial Ethernet 3000 series switches versions 12.2(52)SE through 12.2(52)SE1
Description
The issue arises from the use of well-known SNMP community names,
public for read-only access and private for read-write access, which are hard-coded in the system. This makes it easier for remote attackers to modify the configuration or obtain potentially sensitive information via SNMP requests.Recommendations
For versions 12.2(52)SE and 12.2(52)SE1, perform a Cisco IOS Software upgrade to a version that addresses this issue.
As a temporary workaround, consider deploying the mitigation measures outlined in the Workarounds section to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios
Cisco Industrial Ethernet 3000