PT-2016-1474 · Cisco · Cisco Nx-Os+1

Publicado

2016-03-02

·

Atualizado

2016-12-03

·

CVE-2016-1329

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco NX-OS versions 6.0(2)U6(1) through 6.0(2)U6(5) Cisco NX-OS versions 6.0(2)A6(1) through 6.0(2)A6(5) Cisco NX-OS version 6.0(2)A7(1)
Description The issue is due to hardcoded credentials in the Cisco NX-OS software, allowing remote attackers to obtain root privileges via TELNET or SSH sessions. This could enable an unauthenticated, remote attacker to log in to the device with the privileges of the root user with bash shell access. The vulnerability exists because of a user account with a default and static password, created at installation, which cannot be changed or deleted without impacting system functionality.
Recommendations For Cisco NX-OS versions 6.0(2)U6(1) through 6.0(2)U6(5), update to a version that addresses this vulnerability. For Cisco NX-OS versions 6.0(2)A6(1) through 6.0(2)A6(5), update to a version that addresses this vulnerability. For Cisco NX-OS version 6.0(2)A7(1), update to a version that addresses this vulnerability. As a temporary workaround, consider restricting access to TELNET and SSH sessions until a patch is available.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00775
CVE-2016-1329

Produtos afetados

Cisco Nx-Os
Cisco Nexus