CENTER.HU groups
CENTER.HU address

User:

Guest

www.center.hu / Archive / Security news / january, 2006 / Undocumented root password in Cisco CS-MARS 

Undocumented root password in Cisco CS-MARS

Undocumented root password in Cisco CS-MARS

Madrid, January 13 2006 - Cisco Security Monitoring, Analysis and Response System -CS-MARS (*)- software contains a default password for an undocumented administrative account. Cisco has published version 4.1.3 of CS-MARS to correct the problem.

According to Cisco, version 4.1.2 and earlier of CS-MARS have been distributed with an undocumented user account, with root privileges on the system, with the same password set for all installations of the product.

The account is intended to be used only by authorized Cisco development engineers for advanced debugging purposes. No direct remote access to the root account is permitted as users must first successfully login into the command line interface.

Cisco has released version 4.1.3 of CS-MARS, which allows the default password of the ´expert´ account to be altered through the ˝passwd expert˝ command.

Additional information about the vulnerability and the new version of CS-MARS is available in the Cisco advisory at: http://www.cisco.com/warp/public/707/cisco-sa-20060111-mars.shtml

(*)Cisco Security Monitoring, Analysis and Response System (CS-MARS) is a security system that receives event logs from various network devices, correlates and analyzes the received data for security problems and reports the findings.

Oxygen3 24h-365d
by Panda Software

Back




Copyright © CENTER.HU Ltd, 2000-2010. All rights reserved

sitemap | privacy policy |

copyrights | new pages |

terms of purchase | contact us


PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel