| Vulnerability Name: | CVE-2002-1558 (CCN-10510) | ||||||||
| Assigned: | 2002-10-31 | ||||||||
| Published: | 2002-10-31 | ||||||||
| Updated: | 2018-10-30 | ||||||||
| Summary: | Cisco ONS15454 and ONS15327 running ONS before 3.4 have an account for the VxWorks Operating System in the TCC, TCC+ and XTC that cannot be changed or disabled, which allows remote attackers to gain privileges by connecting to the account via Telnet. | ||||||||
| CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2002-1558 Source: CCN Type: Cisco Systems Inc. Security Advisory, 2002 October 31 at 1600 UTC Cisco ONS15454 and Cisco ONS15327 Vulnerabilities Source: CISCO Type: Patch, Vendor Advisory 20021031 Cisco ONS15454 and Cisco ONS15327 Vulnerabilities Source: XF Type: Patch, Vendor Advisory cisco-ons-default-vsworks-account(10510) Source: CCN Type: OSVDB ID: 8927 Cisco ONS VxWorks Operating System Default Account Source: CCN Type: BID-6073 Cisco ONS15454/ONS15327 Optical Transport Platforms Multiple Vulnerabilities Source: BID Type: Patch, Vendor Advisory 6083 Source: CCN Type: BID-6083 Cisco ONS15454/ONS15327 Optical Transport Platforms Default Account Vulnerability Source: XF Type: UNKNOWN cisco-ons-default-vsworks-account(10510) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||