search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Cisco Content Services Switch (CSS) permits non-privileged user to enter debug mode

Vulnerability Note VU#174248

Original Release Date: 2001-04-28 | Last Revised: 2001-04-28

Overview

A vulnerability in Cisco Content Services Switches (Arrowpoint) allows a valid user to gain administrative access.

Description

Cisco CSS switches run Cisco WebNS software. A user with a valid account on a CSS device can gain unauthorized administrative access to the device. See the Cisco advisory available at http://www.cisco.com/warp/public/707/arrowpoint-useraccnt-debug-pub.shtml for more information.

Impact

Local users can gain administrative access to the switch.

Solution

Update to version 4.01B19s of Cisco WebNS software.

Vendor Information

174248
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Our thanks to Cisco for the information provided in their advisory.

This document was written by Shawn V. Hernan.

Other Information

CVE IDs: CVE-2001-0414
Severity Metric: 13.50
Date Public: 2001-04-04
Date First Published: 2001-04-28
Date Last Updated: 2001-04-28 04:07 UTC
Document Revision: 8

Sponsored by CISA.