Cisco Smart Software Manager On-Prem Static Default Credential Vulnerability
Software Affected
• Cisco Smart Software Manager On-Prem releases prior to 7-202001
Overview
A vulnerability has been reported in the High Availability (HA) service of Cisco Smart Software Manager On-Prem could allow an unauthenticated remote attacker to access a sensitive part of the system with a high -privileged account.
Description
• Cisco Smart Software Manager On-Prem releases prior to 7-202001
Overview
A vulnerability has been reported in the High Availability (HA) service of Cisco Smart Software Manager On-Prem could allow an unauthenticated remote attacker to access a sensitive part of the system with a high -privileged account.
Description
- Cisco Smart Software Manager On-Prem Static Default Credential Vulnerability ( CVE-2020-3158 )
- A vulnerability exists in the High Availability (HA) service of Cisco Smart Software Manager On-Prem due to a system account that has a default and static password and is not under the control of the system administrator. An attacker could exploit this
- vulnerability by using this default account to connect to the affected system. Successful exploitation of this vulnerability could
- allow the attacker to obtain read and write access to system data, including the configuration of an affected device.
Comments
Post a Comment