PT-2016-1474 · Cisco · Cisco Nx-Os+1

Published

2016-03-02

·

Updated

2016-12-03

·

CVE-2016-1329

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco NX-OS versions 6.0(2)U6(1) through 6.0(2)U6(5) Cisco NX-OS versions 6.0(2)A6(1) through 6.0(2)A6(5) Cisco NX-OS version 6.0(2)A7(1)
Description The issue is due to hardcoded credentials in the Cisco NX-OS software, allowing remote attackers to obtain root privileges via TELNET or SSH sessions. This could enable an unauthenticated, remote attacker to log in to the device with the privileges of the root user with bash shell access. The vulnerability exists because of a user account with a default and static password, created at installation, which cannot be changed or deleted without impacting system functionality.
Recommendations For Cisco NX-OS versions 6.0(2)U6(1) through 6.0(2)U6(5), update to a version that addresses this vulnerability. For Cisco NX-OS versions 6.0(2)A6(1) through 6.0(2)A6(5), update to a version that addresses this vulnerability. For Cisco NX-OS version 6.0(2)A7(1), update to a version that addresses this vulnerability. As a temporary workaround, consider restricting access to TELNET and SSH sessions until a patch is available.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00775
CVE-2016-1329

Affected Products

Cisco Nx-Os
Cisco Nexus