Cisco Prime Collaboration Assurance before 11.0 has a hardcoded cmuser account, which allows remote attackers to obtain access by establishing an SSH session and leveraging knowledge of this accounts password, aka Bug ID CSCus62707.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Prime_collaboration_assurance | Cisco | 10.5.1 (including) | 10.5.1 (including) |
Prime_collaboration_assurance | Cisco | 10.6.0 (including) | 10.6.0 (including) |