First published: Tue Mar 18 2003(Updated: )
Cisco ONS15454 and ONS15327 running ONS before 3.4 stores usernames and passwords in cleartext in the image database for the TCC, TCC+ or XTC, which could allow attackers to gain privileges by obtaining the passwords from the image database or a backup.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Optical Networking systems software | =3.0 | |
Cisco Optical Networking systems software | =3.1.0 | |
Cisco Optical Networking systems software | =3.2 | |
Cisco Optical Networking systems software | =3.2.0 | |
Cisco Optical Networking systems software | =3.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1554 is considered a high severity vulnerability due to the exposure of cleartext credentials.
To fix CVE-2002-1554, upgrade the Cisco Optical Networking Systems software to version 3.4 or later.
CVE-2002-1554 affects Cisco ONS 15454 and ONS 15327 running versions before 3.4.
Attackers can exploit CVE-2002-1554 to gain unauthorized access by retrieving cleartext usernames and passwords.
CVE-2002-1554 was published in the year 2002.