First published: Tue Mar 18 2003(Updated: )
Cisco ONS15454 and ONS15327 running ONS before 3.4 have an account for the VxWorks Operating System in the TCC, TCC+ and XTC that cannot be changed or disabled, which allows remote attackers to gain privileges by connecting to the account via Telnet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Optical Network Controller | =3.2 | |
Cisco Optical Network Controller | =3.3.0 | |
Cisco Optical Network Controller | =3.1.0 | |
Cisco Optical Network Controller | =3.2.0 | |
Cisco Optical Network Controller | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1558 is considered a critical vulnerability due to the potential for remote privilege escalation.
To address CVE-2002-1558, upgrade to a fixed version of Cisco Optical Networking Systems Software that is later than 3.4.
CVE-2002-1558 affects Cisco ONS15454 and ONS15327 systems running versions 3.0 to 3.3.0 of the Optical Networking Systems Software.
By exploiting CVE-2002-1558, attackers can gain unauthorized access to the VxWorks Operating System account via Telnet.
There are no known workarounds for CVE-2002-1558; upgrading to a secure version is essential to mitigate the risk.