PT-2020-1707 · Cisco · Cisco Smart Software Manager On-Prem
Published
2020-02-19
·
Updated
2020-02-28
·
CVE-2020-3158
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Smart Software Manager On-Prem (affected versions not specified)
Description
A vulnerability in the High Availability service could allow an unauthenticated, remote attacker to access a sensitive part of the system with a high-privileged account. The issue is due to a system account having a default and static password, which is not under the control of the system administrator. An attacker could exploit this by using the default account to connect to the affected system, potentially gaining read and write access to system data, including device configuration. However, the attacker would not have full administrative rights.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Smart Software Manager On-Prem