The Nortel Networks CVX 1800 Multi-Service Access Switch discloses privileged information.
The CVX 1800 Multi-Service Access Switch is a large modem bank typically used by large carriers and ISP's. When the CVX 1800 is queried with a specially crafted snmpwalk, it will respond with all usernames and passwords for administrator accounts on the vulnerable CVX 1800.
An attacker can gain access to sensitive information such as administrator usernames and passwords. The attacker could then use this information to make unauthorized configuration changes to the CVX 1800.
Upgrade the software on the CVX 1800 to 3.6.3P25.
If the software cannot be upgraded immediately, consider changing the SNMP community string to something other than it's default value of public.
The CERT/CC credits "Michael Rawls"
This document was written by Ian A. Finlay.
|Date First Published:||2002-05-16|
|Date Last Updated:||2004-01-22 22:50 UTC|