PT-2010-3245 · Cisco · Cisco Industrial Ethernet 3000+1

Michael Orlando

·

Published

2010-07-07

·

Updated

2017-08-17

·

CVE-2010-1574

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Industrial Ethernet 3000 series switches versions 12.2(52)SE through 12.2(52)SE1
Description The issue arises from the use of well-known SNMP community names, public for read-only access and private for read-write access, which are hard-coded in the system. This makes it easier for remote attackers to modify the configuration or obtain potentially sensitive information via SNMP requests.
Recommendations For versions 12.2(52)SE and 12.2(52)SE1, perform a Cisco IOS Software upgrade to a version that addresses this issue. As a temporary workaround, consider deploying the mitigation measures outlined in the Workarounds section to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1574

Affected Products

Cisco Ios
Cisco Industrial Ethernet 3000