Slashdot Mirror


Cisco Issues Patch For Nexus Switches To Remove Hardcoded Credentials (csoonline.com)

itwbennett writes: Cisco Systems has released critical software updates for its Nexus 3000 and 3500 switches to remove a default administrative account with static credentials that could allow remote attackers access to a bash shell with root privileges, meaning that they can fully control the device. The account is created at installation time by the Cisco NX-OS software that runs on these switches and it cannot be changed or deleted without affecting the system's functionality, Cisco said in an advisory. The affected devices are: Cisco Nexus 3000 Series switches running NX-OS 6.0(2)U6(1), 6.0(2)U6(2), 6.0(2)U6(3), 6.0(2)U6(4) and 6.0(2)U6(5) and Cisco Nexus 3500 Platform switches running NX-OS 6.0(2)A6(2), 6.0(2)A6(3), 6.0(2)A6(4), 6.0(2)A6(5) and 6.0(2)A7(1).

2 of 36 comments (clear)

  1. Give Cisco a break by flacco · · Score: 4, Funny

    This brash new start-up is still learning the ropes when it comes to networking and security and stuff. I'm sure it wasn't intentional.

    --
    pr0n - keeping monitor glass spotless since 1981.
  2. Because the FBI by minijedimaster · · Score: 5, Funny

    The FBI must have needed access to a single dead terrorist's switch.