Vulnerability Description
Cisco Modular Encoding Platform D9036 Software before 02.04.70 has hardcoded (1) root and (2) guest passwords, which makes it easier for remote attackers to obtain access via an SSH session, aka Bug ID CSCut88070.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Modular Encoding Platform D9036 Software | 02.00.80 |
| Cisco | Modular Encoding Platform D9036 | All versions |
Related Weaknesses (CWE)
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
FAQ
What is CVE-2015-6412?
CVE-2015-6412 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Cisco Modular Encoding Platform D9036 Software before 02.04.70 has hardcoded (1) root and (2) guest passwords, which makes it easier for remote attackers to obtain access via an SSH session, aka Bug I...
How severe is CVE-2015-6412?
CVE-2015-6412 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-6412?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Modular Encoding Platform D9036 Software, Cisco Modular Encoding Platform D9036.