Cisco Application Velocity System Default Password Lets Remote Users Access the System
|
|
SecurityTracker Alert ID: 1019259
|
|
SecurityTracker URL: http://securitytracker.com/id?1019259
|
|
CVE Reference: CVE-2008-0029
(Links to External Site)
|
Date: Jan 23 2008
|
Impact: Root access via network
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Advisory: Cisco Security Advisory
|
Version(s): prior to 5.1.0
|
Description: A vulnerability was reported in Cisco Application Velocity System. A remote user can access the target system.
The system does not prompt users to modify system account default passwords during the initial configuration process. A remote user
with knowledge of the accounts and credentials can access the accounts. Some of the accounts have root level privileges.
Cisco
has assigned Cisco Bug ID CSCsd94732 to this vulnerability.
Cisco discovered this vulnerability through internal testing.
|
Impact: A remote user can access the target system with administrative privileges.
|
Solution: The vendor has issued a fixed version (5.1.0), available for the AVS 3120, 3180, and 3180A systems.
A workaround for the AVS 3110
is described in the Cisco advisory.
The Cisco advisory is available at:
http://www.cisco.com/warp/public/707/cisco-sa-20080123-avs.shtml
|
Vendor URL: www.cisco.com/warp/public/707/cisco-sa-20080123-avs.shtml (Links to External Site)
|
Cause: Configuration error
|
|
Message History:
None.
|
Source Message Contents
|
Date: Wed, 23 Jan 2008 12:13:11 -0500
Subject: Cisco Application Velocity System
|
http://www.cisco.com/warp/public/707/cisco-sa-20080123-avs.shtml
CVE-2008-0029
|
|