Insecure Default Credentials in Cisco Nexus 3000 and 3500 Series Devices
CVE-2016-1329
9.8CRITICAL
Key Information:
- Vendor
- Samsung
- Vendor
- CVE Published:
- 3 March 2016
Summary
Cisco Nexus 3000 and 3500 Series Devices contain hardcoded credentials in specified NX-OS versions that can be exploited by remote attackers to gain root privileges. Utilizing TELNET or SSH sessions, unauthorized users can compromise device security, potentially leading to unauthorized access and control over network equipment. The affected devices must be updated to ensure security against such vulnerabilities.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved