CVE Vulnerabilities

CVE-2015-6389

Improper Authentication

Published: Dec 13, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cisco Prime Collaboration Assurance before 11.0 has a hardcoded cmuser account, which allows remote attackers to obtain access by establishing an SSH session and leveraging knowledge of this accounts password, aka Bug ID CSCus62707.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Prime_collaboration_assuranceCisco10.5.1 (including)10.5.1 (including)
Prime_collaboration_assuranceCisco10.6.0 (including)10.6.0 (including)

Potential Mitigations

References