Cisco Cable Modem Termination System Authentication Bypass Vulnerability
A vulnerability exists in Cisco Systems' uBR7200 series and uBR7100 series Universal Broadband Routers that lets an attacker download unauthorized configuration files to cable modems.
June 17, 2002
Reported June 17, 2002, by CiscoSystems.
VERSIONSAFFECTED
Cisco Systems uBR7200 series and uBR7100 series Universal Broadband Routers
DESCRIPTION
A vulnerability exists in Cisco Systems' uBR7200series and uBR7100 series Universal Broadband Routersthat lets an attacker download unauthorized configuration files to cable modems.A defect, documented as CSCdx72740, lets an intruder create a truncated, invalidconfiguration file that the affected routers improperly accept as valid. Anattacker typically exploits this vulnerability to steal service by reconfiguringthe cable modem to remove bandwidth restrictions that an ISP has put in place.
VENDOR RESPONSE
CiscoSystems has issued a noticeregarding these vulnerabilities and recommends that affected users obtain asoftware upgrade through typical support channels.
CREDIT
Discovered by Cisco Systems.
About the Author
You May Also Like