3 Com Affected

Notified:  August 29, 2001 Updated: September 28, 2001

Status

Affected

Vendor Statement

3Com exited the ATM market in March 2001 - as a result all 3Com ATM products are now obsolete. Therefore, we have no intention at present to address the SNMP ILMI vulnerability issue for the products as reported in VU#976280. For more information, please see the 3Com Commercial Product Obsolescence Policy at http://www.3com.com/products/en_US/discontinued/policy.html

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

Cisco Affected

Notified:  February 27, 2001 Updated: April 06, 2001

Status

Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

Cisco has released an advisory that provides a list of affected products, along with instructions for obtaining fixed software. Because there are many possible combinations of hardware and software configurations, the CERT/CC recommends that all users of IOS software consult the following Cisco Security Advisory: http://www.cisco.com/warp/public/707/ios-snmp-ilmi-vuln-pub.shtml It is important to note that the information leakage aspect of this vulnerability may affect any Cisco product whose IOS software includes ATM support, regardless of whether the product itself has the physical capability to include ATM interfaces. For further details, please consult the Cisco Security Advisory referenced above.

Crosscomm/Olicom Unknown

Updated:  April 06, 2001

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

Juniper Networks Not Affected

Notified:  August 29, 2001 Updated: September 26, 2001

Status

Not Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.