Cisco Catalyst CatOS Authentication Bypass Vulnerability
BID:7424
Info
Cisco Catalyst CatOS Authentication Bypass Vulnerability
| Bugtraq ID: | 7424 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2003 12:00AM |
| Updated: | Apr 24 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to Marco P. Rodrigues. |
| Vulnerable: |
Cisco Catalyst 6500 7.5 (1) Cisco Catalyst 6000 7.5 (1) Cisco Catalyst 4000 7.5 (1) |
| Not Vulnerable: |
Cisco Catalyst 6500 7.6 (1) Cisco Catalyst 6000 7.6 (1) Cisco Catalyst 4000 7.6 (1) |
Discussion
Cisco Catalyst CatOS Authentication Bypass Vulnerability
A vulnerability has been reported for Cisco Catalyst switches that may result in unauthorized access to the enable level.
The vulnerability exists due to the way the 'enable' mode is accessed through the switch.
An attacker who is able to obtain command line access to a vulnerable switch is able to access 'enable' mode without a password.
A vulnerability has been reported for Cisco Catalyst switches that may result in unauthorized access to the enable level.
The vulnerability exists due to the way the 'enable' mode is accessed through the switch.
An attacker who is able to obtain command line access to a vulnerable switch is able to access 'enable' mode without a password.
Exploit / POC
Cisco Catalyst CatOS Authentication Bypass Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Cisco Catalyst CatOS Authentication Bypass Vulnerability
Solution:
This vulnerability is given the Cisco BugID of CSCea42030.
This vulnerability does not affect Catalyst 4000, 6000 and 6500 switches running CatOS 7.6(1). Affected users are advised to contact Cisco to obtain fixes.
Solution:
This vulnerability is given the Cisco BugID of CSCea42030.
This vulnerability does not affect Catalyst 4000, 6000 and 6500 switches running CatOS 7.6(1). Affected users are advised to contact Cisco to obtain fixes.
References
Cisco Catalyst CatOS Authentication Bypass Vulnerability
References:
References: