Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.106210
Category:CISCO
Title:Cisco Catalyst Switches Network Mobility Services Protocol Port Information Disclosure Vulnerability
Summary:Cisco Catalyst Switches running Cisco IOS Software releases prior;to 15.2(2)E1 may allow an unauthenticated, remote attacker to retrieve version information about the software;release running on the device by accessing the Network Mobility Services Protocol (NMSP) port.;;The vulnerability is due to a failure to properly secure NMSP with authentication, which has been;made standard in Cisco IOS Software releases 15.2(2)E1 and later. An attacker could exploit earlier;software releases to map the network and gather information for further attacks.;;Cisco has released software updates that address this vulnerability. Workarounds that address this;vulnerability are not available.
Description:Summary:
Cisco Catalyst Switches running Cisco IOS Software releases prior
to 15.2(2)E1 may allow an unauthenticated, remote attacker to retrieve version information about the software
release running on the device by accessing the Network Mobility Services Protocol (NMSP) port.

The vulnerability is due to a failure to properly secure NMSP with authentication, which has been
made standard in Cisco IOS Software releases 15.2(2)E1 and later. An attacker could exploit earlier
software releases to map the network and gather information for further attacks.

Cisco has released software updates that address this vulnerability. Workarounds that address this
vulnerability are not available.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-1378
Cisco Security Advisory: 20160413 Cisco Catalyst Switches Network Mobility Services Protocol Port Information Disclosure Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160413-nms
http://www.securitytracker.com/id/1035566
CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.