PT-2019-2788 · Cisco+1 · Cisco Findit Network Probe+2

Published

2019-07-17

·

Updated

2019-10-09

·

CVE-2019-1919

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco FindIT Network Management versions 1.1.4 Cisco FindIT Network Probe versions 1.1.4
Description The issue is related to the use of pre-installed credentials in virtual machine images. An attacker could exploit this to gain elevated privileges. The vulnerability is due to the presence of an account with static credentials in the underlying Linux operating system. This could allow an unauthenticated, local attacker to log in to the device with root privileges by accessing the VM console and using the static account.
Recommendations For Cisco FindIT Network Management version 1.1.4, consider changing the static credentials of the pre-installed account to prevent unauthorized access. For Cisco FindIT Network Probe version 1.1.4, change the static credentials of the pre-installed account to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02740
CVE-2019-1919

Affected Products

Cisco Findit Network Management
Cisco Findit Network Probe
Linux