First published: Tue Mar 18 2003(Updated: )
Cisco ONS15454 and ONS15327 running ONS before 3.4 allows remote attackers to modify the system configuration and delete files by establishing an FTP connection to the TCC, TCC+ or XTC using a username and password that does not exist.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Optical Network Controller | =3.2 | |
Cisco Optical Network Controller | =3.3.0 | |
Cisco Optical Network Controller | =3.1.0 | |
Cisco Optical Network Controller | =3.2.0 | |
Cisco Optical Network Controller | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1553 is considered a high severity vulnerability due to its potential for remote attackers to modify system configurations.
To fix CVE-2002-1553, upgrade your Cisco Optical Networking Systems software to version 3.4 or later.
CVE-2002-1553 affects Cisco Optical Networking Systems software versions 3.0, 3.1.0, 3.2, and 3.3.0.
CVE-2002-1553 allows attackers to gain unauthorized FTP access, enabling them to modify configurations and delete files.
CVE-2002-1553 can be exploited using non-existent username and password credentials to gain unauthorized access.