Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Cisco CS-MARS Default Administrative Password Vulnerability

Cisco Security Monitoring, Analysis and Response System (CS-MARS) sets a default administrative password during installation. This password is static across all installations of the software.

Users with authenticated access to the CS-MARS command line interface may use this default password to gain unauthorized administrative access in affected installations.

It is possible for those running software release 4.1.3 and later to change a portion of the default administrative password, effectively addressing the vulnerability. However, earlier versions do not provide this option.







 

Privacy Statement
Copyright 2009, SecurityFocus