Vulnerability Note VU#181721
Alcatel Operating System (AOS) does not require a password for accessing the telnet server
Overview
The OmniSwitch 7700/7800 running Alcatel Operating System (AOS) version 5.1.1 has TCP port 6778 listening as a telnet server. This gives anyone access to the OmniSwitch's Vx-Works operating system without requiring a password.
Description
During an NMAP audit of the AOS 5.1.1 code that runs on the Alcatel OmniSwitch 7700/7800 LAN switches, it was determined a telnet server was listening on TCP port number 6778. This was used during development to access the Wind River Vx-Works operating system. Due to an oversight, this access was not removed prior to product release. |
Impact
Anyone running NMAP on AOS 5.1.1 will see port 6778 listening. The attacker is able to telnet to the port and access the OmniSwitch operating system without a password. This backdoor compromises the entire system. |
Solution
1) Immediate - create an ACL blocking all access to TCP port 6778. |
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Alcatel | Affected | - | 20 Nov 2002 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.alcatel.com/support
- http://www.ind.alcatel.com/nextgen/OmniSwitch_7000_brief.pdf
- http://www.ind.alcatel.com/specs/index.cfm?cnt=7000
Credit
Thanks to Alcatel for reporting this vulnerability.
This document was written by Alcatel's Olivier Paridaens and Jeff Hayes. This document was published by Ian A. Finlay.
Other Information
- CVE IDs: CAN-2002-1272
- CERT Advisory: CA-2002-32
- Date Public: 20 Nov 2002
- Date First Published: 20 Nov 2002
- Date Last Updated: 21 Nov 2002
- Severity Metric: 49.50
- Document Revision: 20
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.