Lucene search

K
ciscoCiscoCISCO-SA-20170607-USF6
HistoryJun 07, 2017 - 4:00 p.m.

Cisco Ultra Services Framework Element Manager Insecure Default Account Information Vulnerability

2017-06-0716:00:00
tools.cisco.com
15

EPSS

0.002

Percentile

54.0%

A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker to log in to the device with the privileges of the root user.

The vulnerability is due to a user account that has a default and static password. An attacker could exploit this vulnerability by connecting to the affected system using this default account. An exploit could allow the attacker to log in with the default credentials, allowing the attacker to gain control of the underlying operating system.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-usf6 [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-usf6”]

Affected configurations

Vulners
Node
ciscoultra_services_framework_element_managerMatchany
OR
ciscoultra_services_framework_element_managerMatchany
VendorProductVersionCPE
ciscoultra_services_framework_element_manageranycpe:2.3:a:cisco:ultra_services_framework_element_manager:any:*:*:*:*:*:*:*

EPSS

0.002

Percentile

54.0%

Related for CISCO-SA-20170607-USF6