Lucene search

K
ciscoCiscoCISCO-SA-20150701-CUCDM
HistoryJul 01, 2015 - 4:00 p.m.

Cisco Unified Communications Domain Manager Default Static Privileged Account Credentials

2015-07-0116:00:00
tools.cisco.com
27

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.002

Percentile

56.2%

A vulnerability in the Cisco Unified Communications Domain Manager Platform Software could allow an unauthenticated, remote attacker to login with the privileges of the root user and take full control of the affected system.

The vulnerability occurs because a privileged account has a default and static password. This account is created at installation and cannot be changed or deleted without impacting the functionality of the system. An attacker could exploit this vulnerability by remotely connecting to the affected system via SSH using this account. An exploit could allow the attacker to take full control over the affected system.

Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150701-cucdm[“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150701-cucdm”]

Affected configurations

Vulners
Node
ciscounified_communications_domain_manager_platformMatchany
OR
ciscounified_communications_domain_manager_platformMatchany
VendorProductVersionCPE
ciscounified_communications_domain_manager_platformanycpe:2.3:a:cisco:unified_communications_domain_manager_platform:any:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.002

Percentile

56.2%

Related for CISCO-SA-20150701-CUCDM