Insecure Default Account Information Vulnerability in Cisco Ultra Services Framework Element Manager
CVE-2017-6692
8.8HIGH
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 13 June 2017
Summary
A vulnerability in Cisco Ultra Services Framework Element Manager permits an authenticated, remote attacker to log in to the device, potentially gaining root-level privileges. This situation arises from insecure default account information, which could lead to unauthorized access and manipulation of sensitive configurations. It is imperative for users to review their security settings as detailed in Cisco's security advisory to mitigate this risk.
Affected Version(s)
Cisco Ultra Services Framework Element Manager Cisco Ultra Services Framework Element Manager
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved