|
|
|
![]() |
Vulnerability Note VU#123140Cisco products contain hard-coded SNMP valuesOverviewCertain versions of the Cisco IOS software have a hard-coded SNMP read-write community string that cannot be changed by an administrator.I. DescriptionSome versions of the Cisco IOS have a hardcoded SNMP read-write community string. This community string is designed to ensure that DOCSIS-compliant cable modems adhere to RFC 2669.A vulnerability exists in the enabling of these strings in Cisco IOS versions which do not run on cable modems. An attacker may be able to take control of an affected device by using standard SNMP commands.
II. ImpactA remote attacker may be able to take control of an affected device.III. SolutionUpdateCisco has released updates that address this issue. Please see Cisco Security Advisory cisco-sa-20060920-docsis for more details.
References
Thanks to Cisco for providing information about this vulnerability. This document was written by Ryan Giobbi.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||