|
|
|
![]() |
Vulnerability Note VU#174248Cisco Content Services Switch (CSS) permits non-privileged user to enter debug modeOverviewA vulnerability in Cisco Content Services Switches (Arrowpoint) allows a valid user to gain administrative access.I. DescriptionCisco CSS switches run Cisco WebNS software. A user with a valid account on a CSS device can gain unauthorized administrative access to the device. See the Cisco advisory available at http://www.cisco.com/warp/public/707/arrowpoint-useraccnt-debug-pub.shtml for more information.II. ImpactLocal users can gain administrative access to the switch.III. SolutionUpdate to version 4.01B19s of Cisco WebNS software.Systems Affected
References
Our thanks to Cisco for the information provided in their advisory. This document was written by Shawn V. Hernan.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||