MEDIUM · 4.6

CVE-2002-1554

Cisco ONS15454 and ONS15327 running ONS before 3.4 stores usernames and passwords in cleartext in the image database for the TCC, TCC+ or XTC, which could allow attackers to gain privileges by obtaini...

Vulnerability Description

Cisco ONS15454 and ONS15327 running ONS before 3.4 stores usernames and passwords in cleartext in the image database for the TCC, TCC+ or XTC, which could allow attackers to gain privileges by obtaining the passwords from the image database or a backup.

CVSS Score

4.6

MEDIUM

AV:L/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
CiscoOptical Networking Systems Software3.0

References

FAQ

What is CVE-2002-1554?

CVE-2002-1554 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Cisco ONS15454 and ONS15327 running ONS before 3.4 stores usernames and passwords in cleartext in the image database for the TCC, TCC+ or XTC, which could allow attackers to gain privileges by obtaini...

How severe is CVE-2002-1554?

CVE-2002-1554 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-1554?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Optical Networking Systems Software.