PT-2019-1535 · Cisco · Cisco Network Assurance Engine
Published
2019-02-12
·
Updated
2023-03-23
·
CVE-2019-1688
CVSS v3.1
7.7
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Network Assurance Engine (NAE) Release 3.0(1)
Description
A vulnerability in the management web interface of Cisco Network Assurance Engine (NAE) could allow an unauthenticated, local attacker to gain unauthorized access or cause a Denial of Service (DoS) condition on the server. The issue is due to a fault in the password management system of NAE, specifically related to the use of default administrator credentials. An attacker could exploit this by authenticating with the default administrator password via the CLI of an affected server, potentially allowing them to view sensitive information or bring the server down.
Recommendations
For Cisco Network Assurance Engine (NAE) Release 3.0(1), change the default administrator password as soon as possible after installation to prevent unauthorized access. Consider restricting access to the management web interface and CLI until the password is changed. As a temporary workaround, limit the use of the default administrator account until a secure password is set.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Network Assurance Engine