CVE Vulnerabilities

CVE-2007-2282

Published: Apr 26, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cisco Network Services (CNS) NetFlow Collection Engine (NFC) before 6.0 has an nfcuser account with the default password nfcuser, which allows remote attackers to modify the product configuration and, when installed on Linux, obtain login access to the host operating system.

Affected Software

NameVendorStart VersionEnd Version
Netflow_collection_engineCisco1.0 (including)1.0 (including)
Netflow_collection_engineCisco2.0 (including)2.0 (including)
Netflow_collection_engineCisco3.0 (including)3.0 (including)
Netflow_collection_engineCisco3.5 (including)3.5 (including)
Netflow_collection_engineCisco3.6 (including)3.6 (including)
Netflow_collection_engineCisco4.0 (including)4.0 (including)
Netflow_collection_engineCisco5.0 (including)5.0 (including)
Netflow_collection_engineCisco5.0.3 (including)5.0.3 (including)

References