CVE-2015-6389
Cisco Prime Collaboration Assurance before 11.0 has a hardcoded cmuser account, which allows remote attackers to obtain access by establishing an SSH session and leveraging knowledge of this account's password, aka Bug ID CSCus62707.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cisco Prime Collaboration Assurance before 11.0 has a hardcoded cmuser account, which allows remote attackers to obtain access by establishing an SSH session and leveraging knowledge of this account's password, aka Bug ID CSCus62707.
- CVSS 2.0
- 9.0 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:C
- EPSS
- 2.60% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- cisco/prime collaboration assurance
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-pcaVendor Advisory
- http://www.securityfocus.com/bid/78738
- http://www.securitytracker.com/id/1034361
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-pcaVendor Advisory
- http://www.securityfocus.com/bid/78738
- http://www.securitytracker.com/id/1034361
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.