SB2018110828 - Authentication bypass (backdoor) in Cisco 550X Series Stackable Managed Switches



SB2018110828 - Authentication bypass (backdoor) in Cisco 550X Series Stackable Managed Switches

Published: November 8, 2018

Security Bulletin ID SB2018110828
Severity
High
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Authentication bypass (backdoor) (CVE-ID: CVE-2018-15439)

The vulnerability allows a remote unauthenticated attacker to bypass authentication mechanism on the target device.

The weakness exist due to the presence of undocumented, static user credentials for the default administrative account. A remote attacker can use a backdoor account to log into the system, bypass authentication and execute arbitrary commands with full admin rights.

Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.