SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#181721

Alcatel Operating System (AOS) does not require a password for accessing the telnet server

Overview

The OmniSwitch 7700/7800 running Alcatel Operating System (AOS) version 5.1.1 has TCP port 6778 listening as a telnet server. This gives anyone access to the OmniSwitch's Vx-Works operating system without requiring a password.

I. Description

During an NMAP audit of the AOS 5.1.1 code that runs on the Alcatel OmniSwitch 7700/7800 LAN switches, it was determined a telnet server was listening on TCP port number 6778. This was used during development to access the Wind River Vx-Works operating system. Due to an oversight, this access was not removed prior to product release.

II. Impact

Anyone running NMAP on AOS 5.1.1 will see port 6778 listening. The attacker is able to telnet to the port and access the OmniSwitch operating system without a password. This backdoor compromises the entire system.

III. Solution

1) Immediate - create an ACL blocking all access to TCP port 6778.
2) Short-term - Alcatel Customer Support has updated code that removes this backdoor. This fix is part of AOS 5.1.1.R02 and AOS 5.1.1.R03. Contact Customer Support for this updated code.
3) Permanent - the generally available AOS code--the code that ships with each OmniSwitch--will have this vulnerability removed as of AOS 5.1.3.

Systems Affected

VendorStatusDate Updated
AlcatelVulnerable20-Nov-2002

References


http://www.alcatel.com/support
http://www.ind.alcatel.com/nextgen/OmniSwitch_7000_brief.pdf
http://www.ind.alcatel.com/specs/index.cfm?cnt=7000

Credit

Thanks to Alcatel for reporting this vulnerability.

This document was written by Alcatel's Olivier Paridaens and Jeff Hayes. This document was published by Ian A. Finlay.

Other Information

Date Public11/20/2002
Date First Published11/20/2002 11:14:30 AM
Date Last Updated11/21/2002
CERT AdvisoryCA-2002-32
CVE NameCAN-2002-1272
US-CERT Technical Alerts 
Metric49.50
Document Revision20

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2002 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader