CVE Vulnerabilities

CVE-2015-6389

Improper Authentication

Published: Dec 13, 2015 | Modified: Dec 07, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:C
RedHat/V2
RedHat/V3
Ubuntu

Cisco Prime Collaboration Assurance before 11.0 has a hardcoded cmuser account, which allows remote attackers to obtain access by establishing an SSH session and leveraging knowledge of this accounts password, aka Bug ID CSCus62707.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Prime_collaboration_assurance Cisco 10.5.1 (including) 10.5.1 (including)
Prime_collaboration_assurance Cisco 10.6.0 (including) 10.6.0 (including)

Potential Mitigations

References