PT-2016-1109 · Cisco · Cisco Modular Encoding Platform D9036

Published

2016-01-22

·

Updated

2016-01-25

·

CVE-2015-6412

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Modular Encoding Platform D9036 Software versions prior to 02.04.70
Description The issue arises from hardcoded root and guest passwords in the software, making it easier for remote attackers to gain access via an SSH session. This could allow a remote attacker to obtain access to sensitive information by establishing an SSH connection.
Recommendations For versions prior to 02.04.70, update to version 02.04.70 or later to resolve the issue. As a temporary workaround, consider restricting SSH access to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00303
CVE-2015-6412

Affected Products

Cisco Modular Encoding Platform D9036