9.8
CVSSv3

CVE-2017-6640

Published: 08/06/2017 Updated: 03/10/2019
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote malicious user to log in to the administrative console of a DCNM server by using an account that has a default, static password. The account could be granted root- or system-level privileges. The vulnerability exists because the affected software has a default user account that has a default, static password. The user account is created automatically when the software is installed. An attacker could exploit this vulnerability by connecting remotely to an affected system and logging in to the affected software by using the credentials for this default user account. A successful exploit could allow the malicious user to use this default user account to log in to the affected software and gain access to the administrative console of a DCNM server. This vulnerability affects Cisco Prime Data Center Network Manager (DCNM) Software releases prior to Release 10.2(1) for Microsoft Windows, Linux, and Virtual Appliance platforms. Cisco Bug IDs: CSCvd95346.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco prime data center network manager 10.1.0

cisco prime data center network manager 10.1\\(2\\)

cisco prime data center network manager 10.1\\(1\\)

Vendor Advisories

A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the administrative console of a DCNM server by using an account that has a default, static password The account could be granted root- or system-level privileges The vulnerability exists because the affected sof ...

Github Repositories

Proof of concept for CVE-2017-6640 as burp extension

CVE-2017-6640-POC Proof of concept for CVE-2017-6640 as burp extension Cisco Prime Data Center Network Manager (DCNM) implements a static credentials See also: toolsciscocom/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-dcnm2 More specifically, the Web UI requires users to authenticate using HTTP Digest Auth This burp extension simply makes use of