Insecure Default Credentials in Cisco Elastic Services Controllers
CVE-2017-6684

8.8HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
13 June 2017

Summary

A vulnerability exists in Cisco Elastic Services Controllers that can permit an authenticated remote attacker to gain unauthorized access to the system as the Linux admin user. This vulnerability stems from the use of insecure default credentials, which can be exploited if not changed during the configuration process. Successful exploitation of this vulnerability may lead to unauthorized system control and compromise sensitive information. It is crucial for users to ensure that default credentials are updated to mitigate this security risk.

Affected Version(s)

Cisco Elastic Services Controller Cisco Elastic Services Controller

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.