First published: Wed Mar 18 2015(Updated: )
The Management Interface on Cisco Content Services Switch (CSS) 11500 devices 8.20.4.02 and earlier allows remote attackers to bypass intended restrictions on local-network device access via crafted SSH packets, aka Bug ID CSCut14855.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Content Services Switch 11500 | <=8.20.4.02 | |
Cisco Content Services Switch 11500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0667 is rated as important due to the potential for remote attackers to bypass restrictions on local-network device access.
To fix CVE-2015-0667, upgrade the Cisco Content Services Switch 11500 to firmware version 8.20.4.03 or later.
CVE-2015-0667 affects Cisco Content Services Switch 11500 devices running firmware version 8.20.4.02 and earlier.
CVE-2015-0667 allows remote attackers to conduct unauthorized access through crafted SSH packets.
Currently, the best workaround for CVE-2015-0667 is to limit SSH access to trusted sources until the firmware can be upgraded.