Vulnerability CVE-2017-12350


Published: 2017-11-16

Description:
A vulnerability in Cisco Umbrella Insights Virtual Appliances 2.1.0 and earlier could allow an authenticated, local attacker to log in to an affected virtual appliance with root privileges. The vulnerability is due to the presence of default, static user credentials for an affected virtual appliance. An attacker could exploit this vulnerability by using the hypervisor console to connect locally to an affected system and then using the static credentials to log in to an affected virtual appliance. A successful exploit could allow the attacker to log in to the affected appliance with root privileges. Cisco Bug IDs: CSCvg31220.

See advisories in our WLB2 database:
Topic
Author
Date
High
Cisco Umbrella Virtual Appliance 2.1.0 Hardcoded Credentials
David Coomber
18.11.2017

Type:

CWE-798

CVSS2 => (AV:L/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.2/10
10/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Cisco -> Umbrella insights virtual appliance 

 References:
http://www.securityfocus.com/bid/101879
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171115-uva
https://www.info-sec.ca/advisories/Cisco-Umbrella-Hardcoded-Credentials.html

Copyright 2024, cxsecurity.com

 

Back to Top