>> 3Com Switches Management Packets Handling Information Disclosure Vulnerability
Title : 3Com Switches Management Packets Handling Information Disclosure Vulnerability VUPEN ID : VUPEN/ADV-2006-4184 CVE ID : CVE-2006-5382
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-10-25
Technical Description
A vulnerability has been identified in 3Com SS3 4400 switches, which could be exploited by attackers to bypass security restrictions and disclose sensitive information. This flaw is due to improper handling of normally restricted management packets, which could be exploited by attackers to cause an affected device to send a response containing the SNMP Read-Write Community string allowing them to disable certain ports or reconfigure VLAN.