CVE-2006-5382
3Com Switch SS3 4400 switches, firmware 5.11, 6.00 and 6.10 and earlier, allow remote attackers to read the SNMP Read-Write Community string and conduct unauthorized actions via unspecified "normally restricted management packets on the device" that…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
3Com Switch SS3 4400 switches, firmware 5.11, 6.00 and 6.10 and earlier, allow remote attackers to read the SNMP Read-Write Community string and conduct unauthorized actions via unspecified "normally restricted management packets on the device" that cause the community string to be returned.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.69% probability · 76th percentile
- CISA KEV
- Not listed
- Affected
- 3com/superstack 3 switch 4400
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/22818
- http://securitytracker.com/id?1017128
- http://www.3com.com/securityalert/alerts/3COM-06-004.html
- http://www.securityfocus.com/bid/20736
- http://www.vupen.com/english/advisories/2006/4184
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29779
- http://secunia.com/advisories/22818
- http://securitytracker.com/id?1017128
- http://www.3com.com/securityalert/alerts/3COM-06-004.html
- http://www.securityfocus.com/bid/20736
- http://www.vupen.com/english/advisories/2006/4184
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29779
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.