Lucene search

K
ciscoCiscoCISCO-SA-20170607-USF4
HistoryJun 07, 2017 - 4:00 p.m.

Cisco Ultra Services Framework Element Manager Insecure Default Credentials Vulnerability

2017-06-0716:00:00
tools.cisco.com
16

EPSS

0.002

Percentile

54.0%

A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker with access to the management network to log in as an admin or oper user of the affected device.

The vulnerability is due to weak, hard-coded credentials of the admin and oper user present on the affected device. An exploit could allow the attacker with access to the management network to log in as an admin or oper user of the affected device.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-usf4 [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-usf4”]

Affected configurations

Vulners
Node
ciscoultra_services_framework_element_managerMatchany
OR
ciscoultra_services_framework_element_managerMatchany
VendorProductVersionCPE
ciscoultra_services_framework_element_manageranycpe:2.3:a:cisco:ultra_services_framework_element_manager:any:*:*:*:*:*:*:*

EPSS

0.002

Percentile

54.0%

Related for CISCO-SA-20170607-USF4