CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:C/I:C/A:C
AI Score
Confidence
High
EPSS
Percentile
90.5%
Cisco IOS 12.2 through 12.4 before 20060920, as used by Cisco IAD2430, IAD2431, and IAD2432 Integrated Access Devices, the VG224 Analog Phone Gateway, and the MWR 1900 and 1941 Mobile Wireless Edge Routers, is incorrectly identified as supporting DOCSIS, which allows remote attackers to gain read-write access via a hard-coded cable-docsis community string and read or modify arbitrary SNMP variables.
Vendor | Product | Version | CPE |
---|---|---|---|
cisco | ios | * | cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:* |
cisco | ios | 12.3(1a) | cpe:2.3:o:cisco:ios:12.3\(1a\):*:*:*:*:*:*:* |
cisco | ios | 12.3(2)ja | cpe:2.3:o:cisco:ios:12.3\(2\)ja:*:*:*:*:*:*:* |
cisco | ios | 12.3(2)ja5 | cpe:2.3:o:cisco:ios:12.3\(2\)ja5:*:*:*:*:*:*:* |
cisco | ios | 12.3(2)jk | cpe:2.3:o:cisco:ios:12.3\(2\)jk:*:*:*:*:*:*:* |
cisco | ios | 12.3(2)jk1 | cpe:2.3:o:cisco:ios:12.3\(2\)jk1:*:*:*:*:*:*:* |
cisco | ios | 12.3(2)t3 | cpe:2.3:o:cisco:ios:12.3\(2\)t3:*:*:*:*:*:*:* |
cisco | ios | 12.3(2)t8 | cpe:2.3:o:cisco:ios:12.3\(2\)t8:*:*:*:*:*:*:* |
cisco | ios | 12.3(2)xa4 | cpe:2.3:o:cisco:ios:12.3\(2\)xa4:*:*:*:*:*:*:* |
cisco | ios | 12.3(2)xa5 | cpe:2.3:o:cisco:ios:12.3\(2\)xa5:*:*:*:*:*:*:* |
secunia.com/advisories/21974
securitytracker.com/id?1016899
www.cisco.com/warp/public/707/cisco-sa-20060920-docsis.shtml
www.kb.cert.org/vuls/id/123140
www.osvdb.org/29034
www.securityfocus.com/bid/20125
www.vupen.com/english/advisories/2006/3722
exchange.xforce.ibmcloud.com/vulnerabilities/29054
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5665