PT-2020-1707 · Cisco · Cisco Smart Software Manager On-Prem

Published

2020-02-19

·

Updated

2020-02-28

·

CVE-2020-3158

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Smart Software Manager On-Prem (affected versions not specified)
Description A vulnerability in the High Availability service could allow an unauthenticated, remote attacker to access a sensitive part of the system with a high-privileged account. The issue is due to a system account having a default and static password, which is not under the control of the system administrator. An attacker could exploit this by using the default account to connect to the affected system, potentially gaining read and write access to system data, including device configuration. However, the attacker would not have full administrative rights.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00940
CVE-2020-3158

Affected Products

Cisco Smart Software Manager On-Prem