The password-sync feature on Belden Hirschmann Classic Platform switches L2B before 05.3.07 and L2E, L2P, L3E, and L3P before 09.0.06 sets an SNMP community to the same string as the administrator password, which allows remote attackers to obtain sensitive information by sniffing the network.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: certcc
Published: 2016-02-18T22:00:00
Updated: 2024-08-05T23:32:20.533Z
Reserved: 2016-02-18T00:00:00
Link: CVE-2016-2509
Vulnrichment
No data.
NVD
Status : Modified
Published: 2016-02-18T22:59:07.853
Modified: 2024-11-21T02:48:35.220
Link: CVE-2016-2509
Redhat
No data.