vendor:
Virtual Central Office 4000 (VCO/4K)
by:
Rex Warren, Brian Carrier, David Goldsmith
8.5
CVSS
HIGH
SNMP Administration Interface
257
CWE
Product Name: Virtual Central Office 4000 (VCO/4K)
Affected Version From: 5.13
Affected Version To: 5.13
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Cisco VCO/4K Password [De]Obfuscator
A vulnerability exists in the Cisco Virtual Central Office 4000 (VCO/4K) programmable voice switch running software versions 5.13 and earlier. The usernames and passwords for the device's SNMP administration interface are protected by a simple substitution cipher which can be easily defeated. As a result, if the 'encrypted' passwords are retrieved, (for example, through the read-only community string) an attacker can obtain a list of valid usernames and passwords potentially allowing an elevation of privileges and possibly more serious consequences.
Mitigation:
Ensure that SNMP is configured with strong passwords and that the passwords are not stored in plaintext.