Vulnerability Name: | CVE-2008-3807 (CCN-45383) | ||||||||
Assigned: | 2008-09-24 | ||||||||
Published: | 2008-09-24 | ||||||||
Updated: | 2022-06-02 | ||||||||
Summary: | Cisco IOS 12.2 and 12.3 on Cisco uBR10012 series devices, when linecard redundancy is configured, enables a read/write SNMP service with "private" as the community, which allows remote attackers to obtain administrative access by guessing this community and sending SNMP requests. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 8.1 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:H/RL:OF/RC:C)
8.1 High (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-3807 Source: CCN Type: SA31990 Cisco IOS Multiple Vulnerabilities Source: SECUNIA Type: Third Party Advisory 31990 Source: CCN Type: SECTRACK ID: 1020941 Cisco uBR10012 Series Devices Grant SNMP Access to Remote Users Source: CISCO Type: Vendor Advisory 20080924 Cisco uBR10012 Series Devices SNMP Vulnerability Source: CCN Type: cisco-sa-20080924-ubr Cisco Security Advisory: Cisco uBR10012 Series Devices SNMP Vulnerability Source: CCN Type: OSVDB ID: 48739 Cisco uBR10012 Series IOS Linecard Redundancy Feature Default SNMP Community Strings Source: SECTRACK Type: Broken Link, Third Party Advisory, VDB Entry 1020941 Source: VUPEN Type: Permissions Required ADV-2008-2670 Source: XF Type: UNKNOWN cisco-ubr10012-snmp-default-string(45383) Source: OVAL Type: Third Party Advisory oval:org.mitre.oval:def:5452 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |