CVE-2016-2509
Published Feb 18, 2016
Last updated 9 years ago
Overview
- Description
- The password-sync feature on Belden Hirschmann Classic Platform switches L2B before 05.3.07 and L2E, L2P, L3E, and L3P before 09.0.06 sets an SNMP community to the same string as the administrator password, which allows remote attackers to obtain sensitive information by sniffing the network.
- Source
- cret@cert.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 5.3
- Impact score
- 3.6
- Exploitability score
- 1.6
- Vector string
- CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 2.9
- Impact score
- 2.9
- Exploitability score
- 5.5
- Vector string
- AV:A/AC:M/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-200
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:belden:hirschmann_firmware:05.3.06:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7966E283-1915-4BAA-8C02-4922744199F5" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:belden:hirschmann_l2b:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "787763C7-9B78-4383-B8DB-AF2278173D0D" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:belden:hirschmann_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BD97A02D-0BF8-48D6-92C7-9320702662E0", "versionEndIncluding": "09.0.05" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:belden:hirschmann_l2e:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "92097AD7-2775-4881-9011-B2807519C884" }, { "criteria": "cpe:2.3:h:belden:hirschmann_l2p:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "AD20C330-7C99-4D5F-AFAA-D67249EA8EFD" }, { "criteria": "cpe:2.3:h:belden:hirschmann_l3e:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "25EE2094-9EFB-485B-B672-397BB868EFB5" }, { "criteria": "cpe:2.3:h:belden:hirschmann_l3p:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "36F994B5-3AE3-449C-BCD2-35EF362B5E16" } ], "operator": "OR" } ], "operator": "AND" } ]