CVE-2000-0267: Medium severity cisco catos vulnerability
Cisco Catalyst 5.4.x allows a user to gain access to the "enable" mode without a password.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure a non-blank enable secret/password and ensure that entering enable mode requires that password; verify no blank or unset enable password is present on affected devices.
Cisco CatOS (enable mode) enable password requirement = require password - Compensating control
Restrict access to device management interfaces (console and vty) to trusted IPs or subnets using ACLs and/or place management interfaces on an isolated management VLAN; limit physical access to management ports.
- Operational
Audit device logs for any unauthorized or unexpected transitions to enable mode and rotate all privileged/enable credentials after applying configuration changes.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0267?
CVE-2000-0267 is considered to have a high severity due to its potential for unauthorized access.
How do I fix CVE-2000-0267?
To fix CVE-2000-0267, you should upgrade to a later version of Cisco CatOS that addresses this vulnerability.
What systems are affected by CVE-2000-0267?
CVE-2000-0267 specifically affects Cisco Catalyst devices running version 5.4(1) of CatOS.
What are the risks associated with CVE-2000-0267?
The risks include unauthorized access to administrative functions, which could lead to network breaches and configuration changes.
Is CVE-2000-0267 still relevant to current systems?
CVE-2000-0267 is less relevant to current systems, but organizations using legacy hardware with the affected CatOS should be aware of it.