CVE-2016-1329
Low
Low
Medium
High
Critical
CVSS Score
Vulnerability Description
Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardcoded credentials, which allows remote attackers to obtain root privileges via a (1) TELNET or (2) SSH session, aka Bug ID CSCuy25800.
Known Affected Software
3 configuration(s) from 3 vendor(s)
x14j_firmware
Version:
t-ms14jakucb-1102.5
CPE:
cpe:2.3:o:samsung:x14j_firmware:t-ms14jakucb-1102.5:*:*:*:*:*:*:*
opensolaris
Version:
snv_124
CPE:
cpe:2.3:o:sun:opensolaris:snv_124:*:*:*:*:*:*:*
keymouse_firmware
Version:
3.08
CPE:
cpe:2.3:o:zzinc:keymouse_firmware:3.08:*:*:*:*:windows:*:*
This vulnerability affects 3 software configuration(s). Ensure you patch all affected systems.
References & Resources
-
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160302-n3kpsirt@cisco.com Vendor Advisory
-
http://www.securitytracker.com/id/1035161psirt@cisco.com
-
https://isc.sans.edu/forums/diary/20795psirt@cisco.com
-
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160302-n3kaf854a3a-2127-422b-91ae-364da2661108 Vendor Advisory
-
http://www.securitytracker.com/id/1035161af854a3a-2127-422b-91ae-364da2661108
-
https://isc.sans.edu/forums/diary/20795af854a3a-2127-422b-91ae-364da2661108
Severity Details
out of 10.0
Low
Weakness Type (CWE)
CWE-287
Top 25 #10
Improper Authentication
- Description
- When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
- Exploit Likelihood
- High
- Typical Severity
- High
- OWASP Top 10
- A07:2021-Identification/Auth Failures
- Abstraction Level
- Class
Key Information
- Published Date
- March 03, 2016
