Nortel CVX 1800 Multi-Service Access Switch Default SNMP Community Vulnerability
BID:4507
Info
Nortel CVX 1800 Multi-Service Access Switch Default SNMP Community Vulnerability
| Bugtraq ID: | 4507 |
| Class: | Design Error |
| CVE: |
CVE-2002-0540 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovery of this issue is credited to Michael Rawls <[email protected]>. |
| Vulnerable: |
Nortel Networks CVX 1800 Multiservice Access Switch 3.6.3 p5 Nortel Networks CVX 1800 Multiservice Access Switch 3.6.3 p25 Nortel Networks CVX 1800 Multiservice Access Switch 3.6.3 p24 |
| Not Vulnerable: | |
Discussion
Nortel CVX 1800 Multi-Service Access Switch Default SNMP Community Vulnerability
Nortel CVX 1800 Multi-Service Access Switch is a hardware modem bank.
The device contains a default SNMP community string of "public", which may allow enable a remote attacker to gain access to sensitive information such as authentication credentials for local accounts on the device, network infrastructure info, etc.
Nortel CVX 1800 Multi-Service Access Switch is a hardware modem bank.
The device contains a default SNMP community string of "public", which may allow enable a remote attacker to gain access to sensitive information such as authentication credentials for local accounts on the device, network infrastructure info, etc.
Exploit / POC
Nortel CVX 1800 Multi-Service Access Switch Default SNMP Community Vulnerability
This issue may be exploited with a SNMP client.
The following example was provided:
snmpwalk CVX-IP-ADD-RESS public .1
This issue may be exploited with a SNMP client.
The following example was provided:
snmpwalk CVX-IP-ADD-RESS public .1
Solution / Fix
Nortel CVX 1800 Multi-Service Access Switch Default SNMP Community Vulnerability
Solution:
Nortel Networks Product Bulletin No. DB022002-1, Issue 3 includes information about a patch that addresses this issue for Version 3.6.3P25. Users are advised to upgrade to Version 3.6.3P25 and then contact the vendor to obtain the patch.
Solution:
Nortel Networks Product Bulletin No. DB022002-1, Issue 3 includes information about a patch that addresses this issue for Version 3.6.3P25. Users are advised to upgrade to Version 3.6.3P25 and then contact the vendor to obtain the patch.
References
Nortel CVX 1800 Multi-Service Access Switch Default SNMP Community Vulnerability
References:
References:
- Nortel CVX 1800 Product Page (Nortel Networks)
- SNMP Technology Page (Nortel Networks)