CVE-2002-1554

3 documents3 sources
Severity
4.6MEDIUM
EPSS
0.1%
top 71.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31
Latest updateApr 30

Description

Cisco ONS15454 and ONS15327 running ONS before 3.4 stores usernames and passwords in cleartext in the image database for the TCC, TCC+ or XTC, which could allow attackers to gain privileges by obtaining the passwords from the image database or a backup.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-253f-6wj2-m9j2: Cisco ONS15454 and ONS15327 running ONS before 32022-04-30
CVEList
CVE-2002-1554: Cisco ONS15454 and ONS15327 running ONS before 32003-03-18
CVE-2002-1554 (MEDIUM CVSS 4.6) | Cisco ONS15454 and ONS15327 running | cvebase.io