CVE-2018-15427
A vulnerability in Cisco Video Surveillance Manager (VSM) Software running on certain Cisco Connected Safety and Security Unified Computing System (UCS) platforms could allow an unauthenticated, remote attacker to log in to an affected system by using the root account, which has default, static user credentials. The vulnerability is due to the presence of undocumented, default, static user credentials for the root account of the affected software on certain systems. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and execute arbitrary commands as the root user.
Published:Oct 5, 2018
Last Modified:Nov 26, 2024
EPS:Oct 5, 2018
EPSS Score:0.12842
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Cisco
Product
Connected Safety And Security Ucs C220
Cisco
Connected Safety And Security Ucs C220
Vendor
Cisco
Product
Video Surveillance Manager
Cisco
Video Surveillance Manager
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
