Cisco Guard And Traffic Anomaly Detector Default Backdoor Account Vulnerability
BID:11959
Info
Cisco Guard And Traffic Anomaly Detector Default Backdoor Account Vulnerability
| Bugtraq ID: | 11959 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2004 12:00AM |
| Updated: | Dec 15 2004 12:00AM |
| Credit: | This vulnerability was disclosed by the vendor. |
| Vulnerable: |
Cisco Guard 3.0 8.12 Cisco Guard 3.0 8 Cisco Anomaly Detector 3.0 8 |
| Not Vulnerable: |
Cisco Guard 3.1 (0) Cisco Anomaly Detector 3.1 (0) |
Discussion
Cisco Guard And Traffic Anomaly Detector Default Backdoor Account Vulnerability
It is reported that Cisco Guard and Anomaly Detector appliances contain a default backdoor account vulnerability.
These appliances contain an undocumented user with a username of 'root', and an unspecified default password. This is an administrative account, with privileges similar to the Unix superuser.
By exploiting this vulnerability, attackers with SSH or HTTPS access to affected devices may gain administrative access.
Versions of Cisco Guard prior to 3.1, and versions of Cisco Anomaly Detector prior to 3.1 are reportedly affected by this vulnerability.
It is reported that Cisco Guard and Anomaly Detector appliances contain a default backdoor account vulnerability.
These appliances contain an undocumented user with a username of 'root', and an unspecified default password. This is an administrative account, with privileges similar to the Unix superuser.
By exploiting this vulnerability, attackers with SSH or HTTPS access to affected devices may gain administrative access.
Versions of Cisco Guard prior to 3.1, and versions of Cisco Anomaly Detector prior to 3.1 are reportedly affected by this vulnerability.
Exploit / POC
Cisco Guard And Traffic Anomaly Detector Default Backdoor Account Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Cisco Guard And Traffic Anomaly Detector Default Backdoor Account Vulnerability
Solution:
Cisco has released version 3.1 of the affected software for both affected devices. Users must contact the vendor for further information regarding downloading fixed software.
Solution:
Cisco has released version 3.1 of the affected software for both affected devices. Users must contact the vendor for further information regarding downloading fixed software.
References
Cisco Guard And Traffic Anomaly Detector Default Backdoor Account Vulnerability
References:
References:
- Anomaly Detector Product Page (Cisco)
- Guard Product Page (CIsco)
- Cisco Security Advisory: Default Administrative Password in Cisco Guard and Traf (Cisco Systems Product Security Incident Response Team
)