← Back

CVE-2020-3446

nvd nist
Published: Aug 26, 2020Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A vulnerability in Cisco Virtual Wide Area Application Services (vWAAS) with Cisco Enterprise NFV Infrastructure Software (NFVIS)-bundled images for Cisco ENCS 5400-W Series and CSP 5000-W Series appliances could allow an unauthenticated, remote attacker to log into the NFVIS CLI of an affected device by using accounts that have a default, static password. The vulnerability exists because the affected software has user accounts with default, static passwords. An attacker with access to the NFVIS CLI of an affected device could exploit this vulnerability by logging into the CLI. A successful exploit could allow the attacker to access the NFVIS CLI with administrator privileges.

Affected (10)

5 products
Encs 5406 W Firmware
Encs 5408 W Firmware
Encs 5412 W Firmware
Csp 5228 W Firmware
Csp 5436 W Firmware
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 6.4(1)
Version 6.4(3d)
Running on/withPlatform Versions
Cisco
Encs 5406 W
All versions
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 6.4(1)
Version 6.4(3d)
Running on/withPlatform Versions
Cisco
Encs 5408 W
All versions
Configuration C
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 6.4(1)
Version 6.4(3d)
Running on/withPlatform Versions
Cisco
Encs 5412 W
All versions
Configuration D
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 6.4(1)
Version 6.4(3d)
Running on/withPlatform Versions
Cisco
Csp 5228 W
All versions
Configuration E
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 6.4(1)
Version 6.4(3d)
Running on/withPlatform Versions
Cisco
Csp 5436 W
All versions

Timeline

No history available yet.