Foundry Networks EdgeIron SNMP Community String Read-Write Vulnerability
BID:4330
Info
Foundry Networks EdgeIron SNMP Community String Read-Write Vulnerability
| Bugtraq ID: | 4330 |
| Class: | Design Error |
| CVE: |
CVE-2002-0478 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 20 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovery of this vulnerability credited to <[email protected]>. |
| Vulnerable: |
Foundry Networks EdgeIron 4802F 0 |
| Not Vulnerable: | |
Discussion
Foundry Networks EdgeIron SNMP Community String Read-Write Vulnerability
EdgeIron switches are high-performance, enterprise-level layer two devices for local area network switching. They are distributed and maintained by Foundry Networks.
It is possible for remote users to write to arbitrary SNMP objects. This is due to EdgeIron switches accepting any community string as a read and write string. By providing a community string of any value with a known SNMP object value, a remote user may alter the contents of the SNMP object.
EdgeIron switches are high-performance, enterprise-level layer two devices for local area network switching. They are distributed and maintained by Foundry Networks.
It is possible for remote users to write to arbitrary SNMP objects. This is due to EdgeIron switches accepting any community string as a read and write string. By providing a community string of any value with a known SNMP object value, a remote user may alter the contents of the SNMP object.