Certain versions of the Cisco IOS software have a hard-coded SNMP read-write community string that cannot be changed by an administrator.
Some versions of the Cisco IOS have a hardcoded SNMP read-write community string. This community string is designed to ensure that DOCSIS-compliant cable modems adhere to RFC 2669.
A vulnerability exists in the enabling of these strings in Cisco IOS versions which do not run on cable modems. An attacker may be able to take control of an affected device by using standard SNMP commands.
A remote attacker may be able to take control of an affected device.
UpdateCisco has released updates that address this issue. Please see Cisco Security Advisory cisco-sa-20060920-docsis for more details.
Thanks to Cisco for providing information about this vulnerability.
|Date First Published:||2006-10-13|
|Date Last Updated:||2006-10-13 20:24 UTC|