Madrid, January 13 2006 - Cisco Security Monitoring, Analysis and Response System -CS-MARS (*)- software contains a default password for an undocumented administrative account. Cisco has published version 4.1.3 of CS-MARS to correct the problem.
According to Cisco, version 4.1.2 and earlier of CS-MARS have been distributed with an undocumented user account, with root privileges on the system, with the same password set for all installations of the product.
The account is intended to be used only by authorized Cisco development engineers for advanced debugging purposes. No direct remote access to the root account is permitted as users must first successfully login into the command line interface.
Cisco has released version 4.1.3 of CS-MARS, which allows the default password of the ´expert´ account to be altered through the ˝passwd expert˝ command.
Additional information about the vulnerability and the new version of CS-MARS is available in the Cisco advisory at: http://www.cisco.com/warp/public/707/cisco-sa-20060111-mars.shtml
(*)Cisco Security Monitoring, Analysis and Response System (CS-MARS) is a security system that receives event logs from various network devices, correlates and analyzes the received data for security problems and reports the findings.
Oxygen3 24h-365d
by Panda Software
Member of IVSZ

Member of SZEK

Acer Affinity Gold partner

Dell Registered Partner
![]()
OKI System Shinrai Partner

XEROX Viszonteladó

APC megbízható szállító

EATON Authorized Partner

Cisco partner

Symantec Software Partner

ESET Partner
![]()
FUJITSU partner

LENOVO Premium Partner

IBM Business Partner

PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel