Monday, April 13, 2015

Unauthenticated SSH port forwarding in Cisco CSS 11500

References:
CISCO:   http://tools.cisco.com/security/center/viewAlert.x?alertId=37889
MITRE:  https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0667

Timeline:
Feb 27 2015: Reported to Cisco PSIRT. Assigned to Incident Manager.
Mar 13 2015: Status check with Incident Manager.
[ Mar 18 2015: Cisco releases IntelliShield ID 37889 ] -- Not copied on this.
Apr 10 2015: Status check with Incident Manager
Apr 13 2015: Incident Manager supplies IntelliShield ID; Finding closed from my end.