PT-2016-1109 · Cisco · Cisco Modular Encoding Platform D9036
Published
2016-01-22
·
Updated
2016-01-25
·
CVE-2015-6412
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Modular Encoding Platform D9036 Software versions prior to 02.04.70
Description
The issue arises from hardcoded
root and guest passwords in the software, making it easier for remote attackers to gain access via an SSH session. This could allow a remote attacker to obtain access to sensitive information by establishing an SSH connection.Recommendations
For versions prior to 02.04.70, update to version 02.04.70 or later to resolve the issue. As a temporary workaround, consider restricting SSH access to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Modular Encoding Platform D9036