Skip to main content

Cisco IOS Linecard Redundancy Unauthorized Access Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 25 Sep 2008 5484 Views

RISK: Medium Risk

Cisco IOS software contains a vulnerability when running on uBR10012 series devices that could allow an unauthenticated, remote attacker to gain privileged access to the device.

The vulnerability exists when the device is configured for linecard redundancy, which is the default setting. The device automatically enables read and write access for SNMP. An attacker could exploit the vulnerability to gain complete control of the device because of the absence of access restrictions on the SNMP communication.


System / Technologies affected

  • Cisco IOS Software Release 12.2BC
  • Cisco IOS Software Release 12.2CX
  • Cisco IOS Software Release 12.2CY
  • Cisco IOS Software Release 12.2XF
  • Cisco IOS Software Release 12.3BC

Solutions

Users with contracts should obtain upgraded software through regular update channels. Most users can obtain upgrades via the Software Center on Cisco's Worldwide Web site at http://www.cisco.com/.

Users without contracts should get their upgrades by contacting the Cisco Technical Assistance Center (TAC). TAC contacts are as follows:

+1 800 553 2447 (toll-free call within North America)
+1 408 526 7209 (toll call from elsewhere in the world)
E-mail: [email protected]


Vulnerability Identifier


Source


Related Link