CVE-2002-1555

Cisco ONS15454 and ONS15327 < 3.4 - Unauthenticated Sensitive Information Exposure via SNMP Community String

Title source: llm
STIX 2.1

Description

Cisco ONS15454 and ONS15327 running ONS before 3.4 uses a "public" SNMP community string that cannot be changed, which allows remote attackers to obtain sensitive information.

References (3)

Core 3
Core References
Patch, Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10507.php
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6081
Patch, Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/warp/public/707/ons-multiple-vuln-pub.shtml

Scores

EPSS 0.0164
EPSS Percentile 74.0%

Details

Status published
Products (5)
cisco/optical_networking_systems_software 3.0
cisco/optical_networking_systems_software 3.1.0
cisco/optical_networking_systems_software 3.2
cisco/optical_networking_systems_software 3.2.0
cisco/optical_networking_systems_software 3.3.0
Published Mar 31, 2003
Tracked Since Feb 18, 2026