Contact | Site en Français               

 


 

Vulnerabilities & Threats

 
  VUPEN Security Advisories
  Linux Security Advisories

  Malware Advisories

  Security Research
  Threat Watch Blog
  Zero-Day Monitor
  Search Engine
  Mailing List & RSS
 
   

>> Cisco IOS Data Over Cable Service Interface Specification SNMP Access Issue

Title : Cisco IOS Data Over Cable Service Interface Specification SNMP Access Issue
VUPEN ID : VUPEN/ADV-2006-3722
CVE ID : CVE-2006-4950
Rated as : High Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2006-09-20


Technical Description    Receive VUPEN Security alerts in a Text format  Receive VUPEN Security alerts in a PDF format  Receive VUPEN Security alerts in an XML format 

A vulnerability has been identified in Cisco IOS running on the Cisco IAD2400 series, 1900 Series Mobile Wireless Edge Routers and Cisco VG224 Analog Phone Gateways, which could be exploited by remote attackers to gain unauthorized access to a vulnerable device. This flaw is due to a design error where a default hard-coded Simple Network Management Protocol (SNMP) community string ("cable-docsis") intended for Data Over Cable Service Interface Specification (DOCSIS) compliant interfaces is enabled on devices configured for SNMP management, which could be exploited by attackers to gain privileged access to a vulnerable device.

Affected Products

Cisco IAD2430 Integrated Access Device
Cisco IAD2431 Integrated Access Device
Cisco IAD2432 Integrated Access Device
Cisco VG224 Analog Phone Gateway
Cisco MWR 1900 Mobile Wireless Edge Router
Cisco MWR 1941 Mobile Wireless Edge Router

Cisco IOS 12.2
Cisco IOS 12.3
Cisco IOS 12.4

Solution

Upgrade to a fixed version :
http://www.cisco.com/warp/public/707/cisco-sa-20060920-docsis.shtml#software

References

http://www.vupen.com/english/advisories/2006/3722
http://www.cisco.com/warp/public/707/cisco-sa-20060920-docsis.shtml

Credits

Vulnerability reported by the vendor

ChangeLog

2006-09-20 : Initial release

Vulnerability Management

Subscribe to VUPEN VNS and receive real-time alerts when new advisories or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form.

 

Vulnerability Alerting

Free 14-Day Trial

 
  Latest News

 

  >> 2009-07-06

     

  Microsoft Windows 0-Day
  Flaw Exploited in the Wild


  >> 2009-06-10

     

  VUPEN Security Research
  Discovered Critical Flaws
  in Adobe Acrobat and MS

  Office Word


  >> 2009-06-02

     

  VUPEN Security Research
  Discovered Critical Flaws
  in ACDSee Products


  >> 2009-05-22

     

  VUPEN Discovered Two
  Critical Vulnerabilities in
  Novell GroupWise 8 / 7

 

 

More Informations    
    








Copyright 2003-2009 © VUPEN.COM - Privacy Policy