First published: Thu Jul 08 2010(Updated: )
IOS 12.2(52)SE and 12.2(52)SE1 on Cisco Industrial Ethernet (IE) 3000 series switches has (1) a community name of public for RO access and (2) a community name of private for RW access, which makes it easier for remote attackers to modify the configuration or obtain potentially sensitive information via SNMP requests, aka Bug ID CSCtf25589.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Cisco IOS | =12.2\(52\)se | |
Puppet Cisco IOS | =12.2\(52\)se1 | |
Cisco IE 3000-4tc Industrial Ethernet switch |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1574 has a medium severity rating due to the potential for unauthorized access and configuration modification.
To fix CVE-2010-1574, change the default community names from 'public' and 'private' to more secure, unique identifiers.
CVE-2010-1574 affects Cisco Industrial Ethernet 3000 series switches running IOS versions 12.2(52)SE and 12.2(52)SE1.
The main risks associated with CVE-2010-1574 include unauthorized access to sensitive information and potential manipulation of network configurations.
Yes, CVE-2010-1574 remains a concern for users of affected Cisco devices that have not updated their community strings for security.