CVE-2010-1574
IOS 12.2(52)SE and 12.2(52)SE1 on Cisco Industrial Ethernet (IE) 3000 series switches has (1) a community name of public for RO access and (2) a community name of private for RW access, which makes it easier for remote attackers to modify the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
IOS 12.2(52)SE and 12.2(52)SE1 on Cisco Industrial Ethernet (IE) 3000 series switches has (1) a community name of public for RO access and (2) a community name of private for RW access, which makes it easier for remote attackers to modify the configuration or obtain potentially sensitive information via SNMP requests, aka Bug ID CSCtf25589.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 4.73% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- cisco/ios · cisco/industrial ethernet 3000
- Source
- psirt@cisco.com
References
- http://osvdb.org/66120
- http://secunia.com/advisories/40407Vendor Advisory
- http://securitytracker.com/id?1024173
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b3891f.shtmlVendor Advisory
- http://www.kb.cert.org/vuls/id/732671US Government Resource
- http://www.securityfocus.com/bid/41436
- http://www.vupen.com/english/advisories/2010/1754
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60145
- http://osvdb.org/66120
- http://secunia.com/advisories/40407Vendor Advisory
- http://securitytracker.com/id?1024173
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b3891f.shtmlVendor Advisory
- http://www.kb.cert.org/vuls/id/732671US Government Resource
- http://www.securityfocus.com/bid/41436
- http://www.vupen.com/english/advisories/2010/1754
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60145
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.