copyright | disclaimer | privacy | contact  
Australia's Leading Computer Emergency Response Team
 
Search this site

 
On this site

 > HOME
 > About AusCERT
 > Membership
 > Contact Us
 > PKI Services
 > Training
 > Publications
 > Sec. Bulletins
 > Conferences
 > News & Media
 > Services
 > Web Log
 > Site Map
 > Site Help
 > Member login





 

ESB-98.074 -- 3Com Security Advisory -- CoreBuilder and SuperStack II vulnerability

Date: 18 May 1998

Click here for printable version
Click here for PGP verifiable version
-----BEGIN PGP SIGNED MESSAGE-----

===========================================================================
              AUSCERT External Security Bulletin Redistribution
                                      
                                      
                    ESB-98.074 -- 3Com Security Advisory
                 CoreBuilder and SuperStack II vulnerability
                                 18 May 1998

===========================================================================

3Com has released the following advisory concerning a vulnerability in
their CoreBuilder LAN switches and SuperStack II Switch products.  This
vulnerability may allow unauthorized access via special logins.

The following security bulletin is provided as a service to AusCERT's
members.  As AusCERT did not write this document, AusCERT has had no
control over its content.  As such, the decision to use any or all of this
information is the responsibility of each user or organisation, and should
be done so in accordance with site policies and procedures.

NOTE: This is only the original release of the security bulletin.  It will
not be updated when the original bulletin is.  If downloading at a later
date, it is recommended that the bulletin is retrieved from the original
authors to ensure that the information is still current.

Contact information for 3Com is included in the Security Bulletin below.
If you have any questions or need further information, please contact them
directly.

Previous advisories and external security bulletins can be retrieved from:

	http://www.auscert.org.au/Information/advisories.html

If you believe that your system has been compromised, contact AusCERT or
your representative in FIRST (Forum of Incident Response and Security
Teams).

Internet Email: auscert@auscert.org.au
Facsimile:	(07) 3365 7031
Telephone:	(07) 3365 4417 (International: +61 7 3365 4417)
		AusCERT personnel answer during Queensland business hours
		which are GMT+10:00 (AEST).
		On call after hours for emergencies.


- --------------------------BEGIN INCLUDED TEXT--------------------

http://www.3com.com/news/advisory51498.html

3Com Security Advisory for CoreBuilder and SuperStack II Customers

3Com is issuing a security advisory affecting select CoreBuilder LAN
switches and
SuperStack II Switch products. This is in response to the widespread
distribution of special
logins intended for service and recovery procedures issued only by 3Com's
Customer
Service Organization under conditions of extreme emergency, such as in the
event of a
customer losing passwords.

Due to this disclosure some 3Com switching products may be vulnerable to
security
breaches caused by unauthorized access via special logins.

To address these issues, customers should immediately log in to their
switches via the
following usernames and passwords. They should then proceed to change the
password
via the appropriate Password parameter to prevent unauthorized access.

CoreBuilder 6000/2500

- - username: debug password: synnet
CoreBuilder 7000

- - username: tech password: tech
SuperStack II Switch 2200

- - username: debug password: synnet
SuperStack II Switch 2700

- - username: tech password: tech


The CoreBuilder 3500, SuperStack II Switch 3900 and 9300 also have these
mechanisms, but
the special login password is changed to match the admin level password
when the admin
level password is changed.

Customers should also immediately change the SNMP Community string from the
default to
a proprietary and confidential identifier known only to authorized network
management
staff. This is due to the fact that the admin password is available through
a specific
proprietary MIB variable when accessed through the read/write SNMP
community string.

This issue applies only to the CoreBuilder 2500/6000/3500 and SuperStack II
Switch
2200/3900/9300.

Fixed versions of software will be available from 3Com for all of these
products by
Wednesday 20th May 1998.

General administration of these systems should still be performed through
the normal
documented usernames and passwords. Other facilities found under these
special logins are
for diagnostic purposes and should only be used under specific guidance
from 3Com's
Customer Service Organization.

For more information 3Com has dedicated a hotline at 1-888-225-1733, or you
can contact
your local 3Com Customer Service location.




Copyright 1998 3Com Corporation. All rights reserved.

- --------------------------END INCLUDED TEXT--------------------


-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv
Comment: ftp://ftp.auscert.org.au/pub/auscert/AUSCERT_PGP.key

iQCVAwUBNWWV6yh9+71yA2DNAQE7kQP9EMzT5ugOAHme0Z3dWWw4tfMyK6EAHqro
RmoSWRLubWP4ndbseTZ4JbSK3Q9jPwGYkJN3DF/qD8OaEMw00+/AgglVuH1LVc19
zdGOQLOU1CRKtI23YfuhIYEFBVtnsYO3yzy7AIXRGqWQFBKA7/RfTsjTQwRL2fo4
zJiuRSmiDdE=
=D3WA
-----END PGP SIGNATURE-----