6.5
CVSSv2

CVE-2015-6316

Published: 06/11/2015 Updated: 06/01/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The default configuration of sshd_config in Cisco Mobility Services Engine (MSE) up to and including 8.0.120.7 allows logins by the oracle account, which makes it easier for remote malicious users to obtain access by entering this account's hardcoded password in an SSH session, aka Bug ID CSCuv40501.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco mobility services engine 7.6.132.0

cisco mobility services engine 8.0_base

cisco mobility services engine 8.0\\(110.0\\)

cisco mobility services engine 7.0_base

cisco mobility services engine 7.4_base

cisco mobility services engine 7.4.100.0

cisco mobility services engine 7.4.110.0

cisco mobility services engine 5.1_base

cisco mobility services engine 6.0_base

cisco mobility services engine 7.4.121.0

cisco mobility services engine 7.6.100.0

cisco mobility services engine 5.2_base

cisco mobility services engine 7.5.102.101

cisco mobility services engine 7.6.120.0

Vendor Advisories

A vulnerability in the Cisco Mobility Services Engine (MSE) could allow an unauthenticated, remote attacker to log in to the MSE with the default oracle account This account does not have full administrator privileges The vulnerability is due to a user account that has a default and static password This account is created at installation and ca ...