|
|
| |
| The Catalyst 3500 XL series switches web configuration interface lets any user execute arbitrary commands on the system without logging in. |
| |
Credit:
The information has been provided by Olle Segerdahl.
|
| |
Vulnerable systems:
Cisco Catalyst 3500 XL series switches
Cisco Catalyst 3500 XL series switches have a built-in web server configuration interface. This interface lets any anonymous web user execute any command without supplying any authentication credentials by simply requesting the /exec location from the web server.
An example follows:
http://catalyst/exec/show/config/cr
This URL will show the configuration file, with all user passwords.
Workaround:
Disable the web configuration interface completely. Await software fix.
Refer to your vendor's documentation for information on how to configure the switch to disable the web configuration interface.
|
|
|
|
|
|
|
|