First published: Thu Feb 26 2009(Updated: )
Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.1) uses default (1) usernames and (2) passwords for (a) the administrator and (b) web management, which makes it easier for remote attackers to perform configuration changes or obtain operating-system access.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Catalyst | =6500 | |
Cisco Catalyst | =7600 | |
Cisco ACE Module | <=0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0620 is classified as a high-severity vulnerability due to the use of default usernames and passwords that can be easily exploited by attackers.
To fix CVE-2009-0620, change the default usernames and passwords used for the administrator and web management interfaces on affected Cisco devices.
CVE-2009-0620 affects the Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers prior to version A2(1.1).
The risks associated with CVE-2009-0620 include unauthorized access and potential configuration changes made by remote attackers.
There is no specific patch for CVE-2009-0620, but the vulnerability can be mitigated by changing default login credentials.