Vulnerability Description
Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, has a default password for the (1) root, (2) cs, and (3) develop accounts, which makes it easier for remote attackers to obtain access via the (a) FTP or (b) SSH daemon, aka Bug ID CSCti54008.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unified Videoconferencing System 5110 Firmware | 7.0.1.13.3 |
| Cisco | Unified Videoconferencing System 5115 Firmware | 7.0.1.13.3 |
| Cisco | Unified Videoconferencing System 5110 | All versions |
| Cisco | Unified Videoconferencing System 5115 | All versions |
| Linux | Linux Kernel | All versions |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2010/Nov/167
- http://www.cisco.com/en/US/products/products_security_response09186a0080b56d0d.hVendor Advisory
- http://www.securityfocus.com/bid/44924
- http://www.securitytracker.com/id?1024753
- http://www.trustmatta.com/advisories/MATTA-2010-001.txt
- http://seclists.org/fulldisclosure/2010/Nov/167
- http://www.cisco.com/en/US/products/products_security_response09186a0080b56d0d.hVendor Advisory
- http://www.securityfocus.com/bid/44924
- http://www.securitytracker.com/id?1024753
- http://www.trustmatta.com/advisories/MATTA-2010-001.txt
FAQ
What is CVE-2010-3038?
CVE-2010-3038 is a vulnerability with a CVSS score of 10.0 (HIGH). Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, has a default password for the (1) root, (2) cs, and (3) develop accounts, which makes it easier fo...
How severe is CVE-2010-3038?
CVE-2010-3038 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-3038?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Unified Videoconferencing System 5110 Firmware, Cisco Unified Videoconferencing System 5115 Firmware, Cisco Unified Videoconferencing System 5110, Cisco Unified Videoconferencing System 5115, Linux Linux Kernel.