[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-4950Date: (C)2006-09-23   (M)2023-12-22


Cisco IOS 12.2 through 12.4 before 20060920, as used by Cisco IAD2430, IAD2431, and IAD2432 Integrated Access Devices, the VG224 Analog Phone Gateway, and the MWR 1900 and 1941 Mobile Wireless Edge Routers, is incorrectly identified as supporting DOCSIS, which allows remote attackers to gain read-write access via a hard-coded cable-docsis community string and read or modify arbitrary SNMP variables.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 10.0
Exploit Score: 10.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1016899
http://www.cisco.com/warp/public/707/cisco-sa-20060920-docsis.shtml
BID-20125
SECUNIA-21974
OSVDB-29034
ADV-2006-3722
VU#123140
ios-docsis-default-snmp(29054)

CPE    60
cpe:/o:cisco:ios:12.3jx
cpe:/o:cisco:ios:12.3ja
cpe:/o:cisco:ios:12.3jk
cpe:/o:cisco:ios:12.4t
...

© SecPod Technologies