search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Nortel Networks CVX 1800 discloses privileged information

Vulnerability Note VU#403315

Original Release Date: 2002-05-16 | Last Revised: 2004-01-22

Overview

The Nortel Networks CVX 1800 Multi-Service Access Switch discloses privileged information.

Description

The CVX 1800 Multi-Service Access Switch is a large modem bank typically used by large carriers and ISP's. When the CVX 1800 is queried with a specially crafted snmpwalk, it will respond with all usernames and passwords for administrator accounts on the vulnerable CVX 1800.

Impact

An attacker can gain access to sensitive information such as administrator usernames and passwords. The attacker could then use this information to make unauthorized configuration changes to the CVX 1800.

Solution

Upgrade the software on the CVX 1800 to 3.6.3P25.

If the software cannot be upgraded immediately, consider changing the SNMP community string to something other than it's default value of public.

Vendor Information

403315
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

The CERT/CC credits "Michael Rawls" for discovering this vulnerability.

This document was written by Ian A. Finlay.

Other Information

CVE IDs: CVE-2002-0540
Severity Metric: 22.50
Date Public: 2002-04-13
Date First Published: 2002-05-16
Date Last Updated: 2004-01-22 22:50 UTC
Document Revision: 28

Sponsored by CISA.