First published: Tue Mar 18 2003(Updated: )
Cisco ONS15454 and ONS15327 running ONS before 3.4 uses a "public" SNMP community string that cannot be changed, which allows remote attackers to obtain sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Optical Networking systems software | =3.0 | |
Cisco Optical Networking systems software | =3.1.0 | |
Cisco Optical Networking systems software | =3.2 | |
Cisco Optical Networking systems software | =3.2.0 | |
Cisco Optical Networking systems software | =3.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1555 is considered to be of medium severity due to its potential to leak sensitive information.
To mitigate CVE-2002-1555, upgrade to a version of the Cisco Optical Networking systems software that is not affected, such as 3.4 or higher.
CVE-2002-1555 affects Cisco Optical Networking systems software versions 3.0, 3.1.0, 3.2, and 3.3.0.
CVE-2002-1555 exposes systems to unauthorized access and information disclosure due to the use of a public SNMP community string.
There is no recommended workaround for CVE-2002-1555; upgrading to a fixed version is the best approach.