Cisco CS-MARS Default Administrative Password Vulnerability
BID:16211
Info
Cisco CS-MARS Default Administrative Password Vulnerability
| Bugtraq ID: | 16211 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 11 2006 12:00AM |
| Updated: | Jan 11 2006 12:00AM |
| Credit: | This issue was reported by the vendor. |
| Vulnerable: |
Nortel Networks Contivity 2000 VPN Switch 4.1.2 Nortel Networks Contivity 2000 VPN Switch 4.1 |
| Not Vulnerable: |
Nortel Networks Contivity 2000 VPN Switch 4.1.3 |
Discussion
Cisco CS-MARS Default Administrative Password Vulnerability
Cisco Security Monitoring, Analysis and Response System (CS-MARS) sets a default administrative password during installation. This password is static across all installations of the software.
Users with authenticated access to the CS-MARS command line interface may use this default password to gain unauthorized administrative access in affected installations.
It is possible for those running software release 4.1.3 and later to change a portion of the default administrative password, effectively addressing the vulnerability. However, earlier versions do not provide this option.
Cisco Security Monitoring, Analysis and Response System (CS-MARS) sets a default administrative password during installation. This password is static across all installations of the software.
Users with authenticated access to the CS-MARS command line interface may use this default password to gain unauthorized administrative access in affected installations.
It is possible for those running software release 4.1.3 and later to change a portion of the default administrative password, effectively addressing the vulnerability. However, earlier versions do not provide this option.
Exploit / POC
Cisco CS-MARS Default Administrative Password Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Cisco CS-MARS Default Administrative Password Vulnerability
Solution:
Cisco has released version 4.1.3 to address this issue. This version is available to Cisco customers with support credentials. It is noted that once this update has been applied, the default password must still be changed with the 'password expert' command. Please refer to the attached Cisco advisory for further info on obtaining upgrades and changing the password.
Nortel Networks Contivity 2000 VPN Switch 4.1
Nortel Networks Contivity 2000 VPN Switch 4.1.2
Solution:
Cisco has released version 4.1.3 to address this issue. This version is available to Cisco customers with support credentials. It is noted that once this update has been applied, the default password must still be changed with the 'password expert' command. Please refer to the attached Cisco advisory for further info on obtaining upgrades and changing the password.
Nortel Networks Contivity 2000 VPN Switch 4.1
-
Cisco CS-MARS 4.1.3
http://www.cisco.com/pcgi-bin/tablebuild.pl/cs-mars?psrtdcat20e2
Nortel Networks Contivity 2000 VPN Switch 4.1.2
-
Cisco CS-MARS 4.1.3
http://www.cisco.com/pcgi-bin/tablebuild.pl/cs-mars?psrtdcat20e2
References
Cisco CS-MARS Default Administrative Password Vulnerability
References:
References: