CVE-2016-2509 Information
Feb 14, 2021
cve
Description
The password-sync feature on Belden Hirschmann Classic Platform switches L2B before 05.3.07 and L2E L2P L3E and L3P before 09.0.06 sets an SNMP community to the same string as the administrator password which allows remote attackers to obtain sensitive information by sniffing the network.
CVSS Vector
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
http://www.kb.cert.org/vuls/id/507216 https://www.belden.com/resourcecenter/security/upload/Belden_Security_Advisory_BSECV-2016-2_1v0.pdf
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: