[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2002-1558Date: (C)2003-03-31   (M)2023-12-22


Cisco ONS15454 and ONS15327 running ONS before 3.4 have an account for the VxWorks Operating System in the TCC, TCC+ and XTC that cannot be changed or disabled, which allows remote attackers to gain privileges by connecting to the account via Telnet.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 10.0
Exploit Score: 10.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
http://www.cisco.com/warp/public/707/ons-multiple-vuln-pub.shtml
BID-6083
cisco-ons-default-vsworks-account(10510)

CPE    8
cpe:/o:cisco:ons_15454_optical_transport_platform:3.3
cpe:/o:cisco:ons_15327:3.0
cpe:/o:cisco:ons_15327:3.2
cpe:/o:cisco:ons_15454_optical_transport_platform:3.0
...

© SecPod Technologies