Description
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if the Telnet protocol is enabled Perform command injection Modify the configuration For more information about these vulnerabilities, see the Details section of this advisory.
Published: 2021-11-04
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-21445 Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if the Telnet protocol is enabled Perform command injection Modify the configuration For more information about these vulnerabilities, see the Details section of this advisory.
History

Thu, 07 Nov 2024 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Cisco Catalyst Pon Switch Cgp-ont-1p Catalyst Pon Switch Cgp-ont-1p Firmware Catalyst Pon Switch Cgp-ont-4p Catalyst Pon Switch Cgp-ont-4p Firmware Catalyst Pon Switch Cgp-ont-4pv Catalyst Pon Switch Cgp-ont-4pv Firmware Catalyst Pon Switch Cgp-ont-4pvc Catalyst Pon Switch Cgp-ont-4pvc Firmware Catalyst Pon Switch Cgp-ont-4tvcw Catalyst Pon Switch Cgp-ont-4tvcw Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-07T21:57:35.782Z

Reserved: 2021-06-15T00:00:00.000Z

Link: CVE-2021-34795

cve-icon Vulnrichment

Updated: 2024-08-04T00:19:48.165Z

cve-icon NVD

Status : Modified

Published: 2021-11-04T16:15:09.053

Modified: 2024-11-21T06:11:13.380

Link: CVE-2021-34795

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses