Re: Cisco 6509 switch telnet vulnerability

From: Bob Niederman (btrq_at_bob-n.com)
Date: 10/04/03

  • Next message: Chris Norton: "Conexant Access Runner DSL Console login bypass vulnerability"
    Date: Sat, 4 Oct 2003 00:55:11 -0500 (CDT)
    To: bugtraq@securityfocus.com
    
    

    While this is clearly a bug, the example given does not show that it's
    serious. The example (and the statement "...as long as they are followed
    by a space and a ?") shows that you have gotten the syntax for the next
    parameter of the command, not that you have executed it.

    ---
    My mail server bit-buckets mail to this address which is not from securityfocus.com servers.  To email me, send to
    bob AT bob-n DOT com
    On 3 Oct 2003, Chris Norton wrote:
    > 
    > 
    > A vulnerability has been found on Cisco 6509 switches. The
    > vulnerability was found to work on 2 different Cisco 6509 switches
    > running CATOS 5.4(2) and 5.5(2). The vulnerability can lead to
    > information and commands being exectued on the remote switch from the
    > login prompt. Commands can be exectued at the Enter password: prompt
    > as long as they are followed by a space and a ? Proof of concept
    > below: Cisco Systems Console
    > 
    > Enter password:
    > <data_size>                Size of the packet (0..1420)
    > <cr>                       
    > Enter password: traceroute 127.0.0.1
    > 
    > This vulnerability has yet to be confirmed by Cisco but they have been alerted about it.
    > 
    

  • Next message: Chris Norton: "Conexant Access Runner DSL Console login bypass vulnerability"

    Relevant Pages

    • Re: [Full-disclosure] FWD Cisco IOS Remote Command Execution Vulnerability
      ... > Vulnerability Alert Cisco IOS Remote Command Execution ... > 9.4 Last Change Cisco has responded to this issue; ... > prone to an issue that may permit gay people to execute arbitrary ... > commands from a password prompt. ...
      (Full-Disclosure)
    • [NEWS] Cisco CatOS Telnet Buffer Vulnerability
      ... Some Cisco Catalyst switches, running CatOS based software releases, have ... a vulnerability wherein a buffer overflow in the telnet option handling ... This vulnerability is documented as Cisco bug ID CSCdw19195. ...
      (Securiteam)
    • Re: Help Please
      ... Theoretically you may script it through a Terminal software under Windows. ... has pretty good commands set. ... Basically you can open a file with list of switches you want ... Headset Adapters for Cisco IP Phones ...
      (comp.dcom.sys.cisco)
    • Re: Sniffing packets on the wire
      ... > Just to add to that: some time ago Cisco had a vulnerability in the ... > Web management interface of their switches, ... I observe switches that have ...
      (microsoft.public.security)
    • [Full-disclosure] Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA Adaptive Securi
      ... Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA Adaptive ... Security Appliance and Cisco PIX Security Appliances ... Crafted HTTP packet denial of service vulnerability ... Crafted H.323 packet DoS vulnerability ...
      (Full-Disclosure)