CVE-2016-15058: Hirschmann HiLCOS Classic Platform Password Exposure via SNMP
Hirschmann HiLCOS Classic Platform switches Classic L2E, L2P, L3E, L3P versions prior to 09.0.06 and Classic L2B prior to 05.3.07 contain a credential exposure vulnerability where user passwords are synchronized with SNMPv1/v2 community strings and transmitted in plaintext when the feature is enabled. Attackers with local network access can sniff SNMP traffic or extract configuration data to recover plaintext credentials and gain unauthorized administrative access to the switches.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Hirschmann HiLCOS Classic Platform switchesto a version that resolves this vulnerability.Fixed in 09.0.06 - Upgrade
Upgrade
Hirschmann HiLCOS Classic Platform switchesto a version that resolves this vulnerability.Fixed in 05.3.07 - Compensating control
Disable the feature that synchronizes/sends user passwords via SNMPv1/v2 community strings over the network, since it transmits passwords in plaintext when enabled.
Event History
Frequently Asked Questions
What is the severity of CVE-2016-15058?
CVE-2016-15058 is classified as a credential exposure vulnerability due to inadequate password protection.
How do I fix CVE-2016-15058?
To fix CVE-2016-15058, update the Hirschmann HiLCOS Classic Platform to versions 09.0.06 or higher for Classic L2E, L2P, L3E, L3P, or to version 05.3.07 or higher for Classic L2B.
What products are affected by CVE-2016-15058?
CVE-2016-15058 affects Hirschmann HiLCOS Classic Platform switches, specifically Classic L2E, L2P, L3E, L3P versions prior to 09.0.06 and Classic L2B prior to 05.3.07.
What causes CVE-2016-15058?
CVE-2016-15058 is caused by user passwords being synchronized with SNMPv1/v2 community strings, leading to potential unauthorized access.
Is there a workaround for CVE-2016-15058?
There are no officially documented workarounds for CVE-2016-15058, and the recommended solution is to update to the latest software versions.