Vulnerability Description
Cisco Application Networking Manager (ANM) before 2.0 uses a default MySQL root password, which makes it easier for remote attackers to execute arbitrary operating-system commands or change system files.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Application Networking Manager | <= 1.2 |
Related Weaknesses (CWE)
References
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080a7bc84.sVendor Advisory
- http://www.securityfocus.com/bid/33903
- http://www.securitytracker.com/id?1021771
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080a7bc84.sVendor Advisory
- http://www.securityfocus.com/bid/33903
- http://www.securitytracker.com/id?1021771
FAQ
What is CVE-2009-0617?
CVE-2009-0617 is a vulnerability with a CVSS score of 10.0 (HIGH). Cisco Application Networking Manager (ANM) before 2.0 uses a default MySQL root password, which makes it easier for remote attackers to execute arbitrary operating-system commands or change system fil...
How severe is CVE-2009-0617?
CVE-2009-0617 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-0617?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Application Networking Manager.