Lucene search

K
cveCiscoCVE-2013-5522
HistoryOct 25, 2013 - 3:52 a.m.

CVE-2013-5522

2013-10-2503:52:54
CWE-264
cisco
web.nvd.nist.gov
25
cisco
ios
catalyst 3750x
service module
credentials
local users
privileges
bug id
cscue92286

CVSS2

6.8

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:C/I:C/A:C

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

5.1%

Cisco IOS on Catalyst 3750X switches has default Service Module credentials, which makes it easier for local users to gain privileges via a Service Module login, aka Bug ID CSCue92286.

Affected configurations

Nvd
Node
ciscoiosMatch-
AND
ciscocatalyst_3750-x
VendorProductVersionCPE
ciscoios-cpe:2.3:o:cisco:ios:-:*:*:*:*:*:*:*
ciscocatalyst_3750-x*cpe:2.3:h:cisco:catalyst_3750-x:*:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:C/I:C/A:C

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

5.1%

Related for CVE-2013-5522