CVE-2014-0709
published 2014-02-22CVE-2014-0709: Cisco UCS Director (formerly Cloupia) before 4.0.0.3 has a hardcoded password for the root account, which makes it easier for remote attackers to obtain…
PriorityP351critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
1.84%
76.7th percentile
Cisco UCS Director (formerly Cloupia) before 4.0.0.3 has a hardcoded password for the root account, which makes it easier for remote attackers to obtain administrative access via an SSH session to the CLI interface, aka Bug ID CSCui73930.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ucs_director | <= 4.0.0.2 | — |
| cisco | ucs_director | — | — |
| cisco | ucs_director | — | — |
| cisco | ucs_director_default_credentials | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r7vj-ghvm-j3pp: Cisco UCS Director (formerly Cloupia) before 4
ghsa_unreviewed·2022-05-17
CVE-2014-0709 [HIGH] GHSA-r7vj-ghvm-j3pp: Cisco UCS Director (formerly Cloupia) before 4
Cisco UCS Director (formerly Cloupia) before 4.0.0.3 has a hardcoded password for the root account, which makes it easier for remote attackers to obtain administrative access via an SSH session to the CLI interface, aka Bug ID CSCui73930.
Cisco
Cisco UCS Director Default Credentials Vulnerability
vendor_cisco·2014-02-20·CVSS 9.3
CVE-2014-0709 [CRITICAL] CWE-255 Cisco UCS Director Default Credentials Vulnerability
Cisco UCS Director Default Credentials Vulnerability
A vulnerability in Cisco Unified Computing System (UCS) Director could allow an unauthenticated, remote attacker to take complete control of the affected device.
The vulnerability is due to a default root user account created during installation. An attacker could exploit this vulnerability by accessing the server command-line interface (CLI) remotely using the default account credentials. An exploit could allow the attacker to log in with the default credentials, which provide full administrative rights to the system.
Cisco has released software updates that address this vulnerability.
Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/s
Cisco
Cisco UCS Director Default Credentials Vulnerability
vendor_cisco
CVE-2014-0709 Cisco UCS Director Default Credentials Vulnerability
CVE-2014-0709: Cisco UCS Director Default Credentials Vulnerability
A vulnerability in Cisco Unified Computing System (UCS) Director could allow an unauthenticated, remote attacker to take complete control of the affected device. The vulnerability is due to a default root user account created during installation. An attacker could exploit this vulnerability by accessing the server command-line interface (CLI) remotely using the default account credentials. An exploit could allow the attacker to log in with the default credentials, which provide full administrative rights to the system. Cisco has released software updates that address this vulnerability.
CWE: CWE-255, CWE-255
Bug IDs: CSCui73930, CSCui73930
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-02-22
Published