3 ms·
Does it though? Are you a SWE?
by freshpots 4y ago
Does it though? Are you a SWE?
- fbdab103 4y agoGiven the number of times that a hard-coded password has been distributed on Cisco gear, yeah, I think it points to a cultural failure.
- Spooky23 4y agoThat happened 15 years ago dude, on Linksys gear. The first CVE on that list is probably older than a few of the commenters on this thread.
- fbdab103 4y agoA cursory internet search reveals several that popped up within the past decade on Cisco's gear. Hard-coded passwords are table stakes, if that slips through, what else is lurking beneath the surface? Network hardware is to operate in the adversarial landscape which is the open internet. It requires an extreme, exhaustive workflow to ensure bugs do not slip through. That we repeatedly see these failures does not raise confidence. - 2016-01 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160113-air https://tools.cisco.com/security/center/content/CiscoSecurit... - 2018-03 https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20180307-cpcp.html https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-2018... - 2018-10 https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20181003-cpcp-password.html https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-2018... - 2019-07 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190717-cfnm-statcred https://tools.cisco.com/security/center/content/CiscoSecurit... Edit: formatting