First published: Fri Oct 25 2013(Updated: )
Cisco IOS on Catalyst 3750X switches has default Service Module credentials, which makes it easier for local users to gain privileges via a Service Module login, aka Bug ID CSCue92286.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | ||
Cisco Catalyst 3750X-24P-L |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5522 has a CVSS base score of 7.5, indicating a high severity vulnerability.
To fix CVE-2013-5522, change the default Service Module credentials to strong, unique passwords.
CVE-2013-5522 affects Cisco IOS on Catalyst 3750X switches.
CVE-2013-5522 is a local privilege escalation vulnerability due to default credentials.
CVE-2013-5522 requires local access for exploitation, making it less critical than remote vulnerabilities.