Insecure Default Credentials in Cisco Ultra Services Framework Element Manager
CVE-2017-6686
8.8HIGH
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 13 June 2017
Summary
A vulnerability exists in Cisco Ultra Services Framework Element Manager, which could allow an authenticated remote attacker with access to the management network to log in as an administrator or operator on the affected device. This issue arises from the presence of insecure default credentials, potentially compromising the security of the management interface. Organizations using this product should take immediate steps to mitigate risks by updating to the latest versions and applying recommended security practices.
Affected Version(s)
Cisco Ultra Services Framework Element Manager Cisco Ultra Services Framework Element Manager
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved