First published: Fri Sep 26 2008(Updated: )
Cisco IOS 12.2 and 12.3 on Cisco uBR10012 series devices, when linecard redundancy is configured, enables a read/write SNMP service with "private" as the community, which allows remote attackers to obtain administrative access by guessing this community and sending SNMP requests.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | =12.3bc | |
Cisco IOS | =12.2cy | |
Cisco IOS | =12.2bc | |
Cisco IOS | =12.2cx | |
Cisco IOS | =12.2xf |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3807 is rated as a high severity vulnerability due to the potential for remote administrative access.
To fix CVE-2008-3807, change the default SNMP community string from 'private' to something more secure.
CVE-2008-3807 affects Cisco IOS versions 12.2 and 12.3 on Cisco uBR10012 series devices.
Yes, CVE-2008-3807 can be exploited remotely by attackers who successfully guess the SNMP community string.
SNMP, or Simple Network Management Protocol, is the service that is vulnerable in CVE-2008-3807, allowing unauthorized access.