>> Cisco IOS Data Over Cable Service Interface Specification SNMP Access Issue
Title : Cisco IOS Data Over Cable Service Interface Specification SNMP Access Issue VUPEN ID : VUPEN/ADV-2006-3722 CVE ID : CVE-2006-4950
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-09-20
Technical Description
A vulnerability has been identified in Cisco IOS running on the Cisco IAD2400 series, 1900 Series Mobile Wireless Edge Routers and Cisco VG224 Analog Phone Gateways, which could be exploited by remote attackers to gain unauthorized access to a vulnerable device. This flaw is due to a design error where a default hard-coded Simple Network Management Protocol (SNMP) community string ("cable-docsis") intended for Data Over Cable Service Interface Specification (DOCSIS) compliant interfaces is enabled on devices configured for SNMP management, which could be exploited by attackers to gain privileged access to a vulnerable device.