Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Cisco patches switches to remove hardcoded credentials
iTnews (AUS) ^ | Mar 4 2016 7:53AM (AUS) | Juha Saarinen

Posted on 03/04/2016 6:59:10 PM PST by Utilizer

Cisco has issued a patch for its Nexus 3000 series and Nexus 3500 platform switches to remove a hardcoded password for a user account which would allow attackers full remote access.

In a security advisory, Cisco said the account "could allow an unauthenticated, remote attacker to log in to the device with the privileges of the root user with bash [command] shell access."

Remote access is possible via Telnet, or by Secure Shell on a specific release of the NX operating system. Serial console access locally is also possible.

Cisco said the account is created during installation on the devices and cannot be changed or removed without affecting system functionality.

The company suggested administrators disable the Telnet server on the Nexus devices as a workaround and use SSH instead.

(Excerpt) Read more at itnews.com.au ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: hardware; networking; security
Heavy network users beware...
1 posted on 03/04/2016 6:59:10 PM PST by Utilizer
[ Post Reply | Private Reply | View Replies]

To: Utilizer

Kind of silly .. if you care at all about security you always disable telnet


2 posted on 03/04/2016 7:07:12 PM PST by tophat9000 (King G(OP)eorge III has no idea why the Americans are in rebellion... teach him why)
[ Post Reply | Private Reply | To 1 | View Replies]

To: tophat9000

Ive worked with Nexus 2, 5 and 7 k


3 posted on 03/04/2016 7:09:38 PM PST by tophat9000 (King G(OP)eorge III has no idea why the Americans are in rebellion... teach him why)
[ Post Reply | Private Reply | To 2 | View Replies]

To: tophat9000

Exactly.

And if you have any sense, you disable password authentication in ssh.


4 posted on 03/04/2016 7:19:31 PM PST by jdege
[ Post Reply | Private Reply | To 2 | View Replies]

To: jdege; tophat9000
> if you care at all about security you always disable telnet

> if you have any sense, you disable password authentication in ssh

Yes, of course. Those are standard practice... for those who "care" and have any "sense".

You would be appalled at how many admins DO NOT do/have either of those things.

5 posted on 03/04/2016 7:30:47 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 4 | View Replies]

To: Utilizer

Telnet on a consumer facing internet connection. Idiots.


6 posted on 03/04/2016 7:36:48 PM PST by soycd
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
Yea but a sys admin should not be installing a Cisco Nexus 3000 switch's...their are top of rack data center grade switches..so installed by a network engineer to a reviewed config template

Nexus is not your average Cisco switch

... That being said... ive seen some really stupid things done in networks....

7 posted on 03/04/2016 7:49:54 PM PST by tophat9000 (King G(OP)eorge III has no idea why the Americans are in rebellion... teach him whygrade switches)
[ Post Reply | Private Reply | To 5 | View Replies]

To: tophat9000

But if you have any sense also, you would not allow anyone to use “password” as the password to any login, yet year after year so many people continue to do so time and time again.

Rather like using the locking combination 1-2-3-4-5 on your luggage, LOL.


8 posted on 03/04/2016 8:18:06 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 2 | View Replies]

To: jdege

This machine is set up to always use TLS wherever possible. I use https: whenever possible.

Have plugin to disable Java scripts unless I allow them. Only have a few that are default allowed.

It has helped. It does cause some issues when logging onto sites with a dozen scripts running. I hate them. Normally avoid the sites.

It certainly made what I show to the web much much smaller.


9 posted on 03/04/2016 8:48:31 PM PST by Texas Fossil ((Texas is not where you were born, but a Free State of Heart, Mind & Attitude!))
[ Post Reply | Private Reply | To 4 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson