Re: Cisco 6509 switch telnet vulnerability

From: Wendy Garvin (wgarvin_at_cisco.com)
Date: 10/04/03

  • Next message: FreeBSD Security Advisories: "FreeBSD Security Advisory FreeBSD-SA-03:18.openssl"
    Date: Fri, 3 Oct 2003 18:11:31 -0700
    To: kicktd@hotmail.com, bugtraq@securityfocus.com
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    Chris,

    This is a known bug, and we were able to reproduce the behavior you
    reported, however the commands cannot actually be executed. As you
    demonstrated, you can get the 'help' text for non-enable commands at the
    password prompt, but the command is not completed, all that is returned is
    an error message. These commands are publicly available:

    http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/sw_5_5/cmd_refr/cli.htm

    This bug cannot be used to gain control of the switch, gather further
    information about the device or gather details about the traffic it carries.
    It is documented as CSCdr87435, and it is fixed in 5.5(3) and later, and
    6.1(1) and later. Details about the problem can be found on our website if
    you are a registered user:

    http://www.cisco.com/pcgi-bin/Support/Bugtool/onebug.pl?bugid=CSCdr87435

    Thank you for your work on this problem. As always, working with the Cisco
    PSIRT team is the best way to verify the accuracy of information before
    posting it publicly.

    - ---Wendy

    > Chris Norton <kicktd@hotmail.com> [2003-10-03 16:24] wrote:
    >
    >
    > A vulnerability has been found on Cisco 6509 switches. The vulnerability was found to work on 2 different Cisco 6509 switches running CATOS 5.4(2) and 5.5(2). The vulnerability can lead to information and commands being exectued on the remote switch from the login prompt. Commands can be exectued at the Enter password: prompt as long as they are followed by a space and a ?
    > Proof of concept below:
    > Cisco Systems Console
    >
    > Enter password:
    > <data_size> Size of the packet (0..1420)
    > <cr>
    > Enter password: traceroute 127.0.0.1
    >
    > This vulnerability has yet to be confirmed by Cisco but they have been alerted about it.
    >
    > [ ----- End of Included Message ----- ]

    - ---
    Wendy Garvin - Cisco PSIRT - 408 525-1888 CCIE# 6526
    - -----------------------------------------------------
               http://www.cisco.com/go/psirt

    -----BEGIN PGP SIGNATURE-----
    Version: PGP 6.5.2

    iQA/AwUBP34brc/6vhuARK9tEQICAgCgj7ghQcOp0poO7TPsRyHEI+oe50MAoOBo
    BHjtXy3ob12Ss7bouy3JpARY
    =RIWI
    -----END PGP SIGNATURE-----


  • Next message: FreeBSD Security Advisories: "FreeBSD Security Advisory FreeBSD-SA-03:18.openssl"

    Relevant Pages

    • Re: SQLCeCommandBuilder...ITS A BUG...
      ... In order to evade this bug, you must update the dataset with the exact same ... Start by looking at the actual commands the command builder builds for ... Dim dcConn As New SqlCeConnection ... Dim cb As New SqlCeCommandBuilder() ...
      (microsoft.public.dotnet.framework.compactframework)
    • Re: [opensuse] Please vote for Dolphin Crashes when connecting to MS share
      ... This bug has been around for a while and I think I'm the only voter. ... To unsubscribe, e-mail: opensuse+unsubscribe@xxxxxxxxxxxx ... For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx ... Head of EDD Tape Extraction and Processing team ...
      (SuSE)
    • Re: [SLE] find command in SuSE 9.2 dont work properly
      ... Find does not have a bug. ... explaining real facts and using valid logic. ... I do, however, feel some duty to defend facts and logic against the ... For additional commands send e-mail to suse-linux-e-help@suse.com ...
      (SuSE)
    • Re: [LogoForum] Re: Programming in mswlogo can be surprising
      ... only device drivers should be able to do.  This is bad for FMSLogo, ... Why don't the mswlogo fans share their work om the net. ... I just tested out a fix for this bug and it worked.  You can expect ... commands to do what you want, ...
      (comp.lang.logo)
    • bug in fzero
      ... The following commands cause matlab 7.0.4 to hang; ... maximum iteration count, but fzero does not have this. ... This bug has been reported to Mathworks and hopefully will be fixed ...
      (comp.soft-sys.matlab)

  • Quantcast