SB2018110828 - Authentication bypass (backdoor) in Cisco 550X Series Stackable Managed Switches
Published: November 8, 2018
Security Bulletin ID
SB2018110828
Severity
High
Patch available
NO
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Authentication bypass (backdoor) (CVE-ID: CVE-2018-15439)
The vulnerability allows a remote unauthenticated attacker to bypass authentication mechanism on the target device.The weakness exist due to the presence of undocumented, static user credentials for the default administrative account. A remote attacker can use a backdoor account to log into the system, bypass authentication and execute arbitrary commands with full admin rights.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.