5
CVSSv2

CVE-2015-4196

Published: 04/07/2015 Updated: 28/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Platform Software prior to 4.4.5 in Cisco Unified Communications Domain Manager (CDM) 8.x has a hardcoded password for a privileged account, which allows remote malicious users to obtain root access by leveraging knowledge of this password and entering it in an SSH session, aka Bug ID CSCuq45546.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified communications domain manager 4.4.3

cisco unified communications domain manager 4.4.1

cisco unified communications domain manager 4.4.2

cisco unified communications domain manager 4.4.4

Vendor Advisories

A vulnerability in the Cisco Unified Communications Domain Manager Platform Software could allow an unauthenticated, remote attacker to login with the privileges of the root user and take full control of the affected system The vulnerability occurs because a privileged account has a default and static password This account is created at installa ...