CVE-2010-1574: Critical severity puppet cisco ios vulnerability
IOS 12.2(52)SE and 12.2(52)SE1 on Cisco Industrial Ethernet (IE) 3000 series switches has (1) a community name of public for RO access and (2) a community name of private for RW access, which makes it easier for remote attackers to modify the configuration or obtain potentially sensitive information via SNMP requests, aka Bug ID CSCtf25589.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1574?
CVE-2010-1574 has a medium severity rating due to the potential for unauthorized access and configuration modification.
How do I fix CVE-2010-1574?
To fix CVE-2010-1574, change the default community names from 'public' and 'private' to more secure, unique identifiers.
Which devices are affected by CVE-2010-1574?
CVE-2010-1574 affects Cisco Industrial Ethernet 3000 series switches running IOS versions 12.2(52)SE and 12.2(52)SE1.
What risks are associated with CVE-2010-1574?
The main risks associated with CVE-2010-1574 include unauthorized access to sensitive information and potential manipulation of network configurations.
Is CVE-2010-1574 still a concern for users?
Yes, CVE-2010-1574 remains a concern for users of affected Cisco devices that have not updated their community strings for security.