Cisco Nexus 9000 Switches Allow SSH As Root
nvd.nist.gov
Cisco Nexus 9000 Switches Allow SSH As Root
1–10 of 113 posts
Re: Cisco Nexus 9000 Switches Allow SSH As Root
#2Re: Cisco Nexus 9000 Switches Allow SSH As Root
#3The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.
Re: Cisco Nexus 9000 Switches Allow SSH As Root
#4This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.
It’s “allow ssh as root with a publicly available ssh key”. Your version is making it sound mundane.
Re: Cisco Nexus 9000 Switches Allow SSH As Root
#5This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.
Which makes it even more likely to be explained by stupidity as to malice.
Re: Cisco Nexus 9000 Switches Allow SSH As Root
#6This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.
You’re joking right? It’s “allow ssh as root with a publicly available ssh key”. Your version is making it sound mundane.
Re: Cisco Nexus 9000 Switches Allow SSH As Root
#7This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.
You’re joking right? It’s “allow ssh as root with a publicly available ssh key”. Your version is making it sound mundane.
Re: Cisco Nexus 9000 Switches Allow SSH As Root
#8This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.
Backdoor definition: "A backdoor is a method, often secret, of bypassing normal authentication in a computer system."
Re: Cisco Nexus 9000 Switches Allow SSH As Root
#9This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.
It allows anyone who knows the default SSH key pair to login as root. How is that not a backdoor? Backdoor definition: "A backdoor is a method, often secret, of bypassing normal authentication in a computer system."