CVE-2015-4196
published 2015-07-04CVE-2015-4196: Platform Software before 4.4.5 in Cisco Unified Communications Domain Manager (CDM) 8.x has a hardcoded password for a privileged account, which allows remote…
PriorityP335medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.95%
77.9th percentile
Platform Software before 4.4.5 in Cisco Unified Communications Domain Manager (CDM) 8.x has a hardcoded password for a privileged account, which allows remote attackers to obtain root access by leveraging knowledge of this password and entering it in an SSH session, aka Bug ID CSCuq45546.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_domain_manager | — | — |
| cisco | unified_communications_domain_manager | — | — |
| cisco | unified_communications_domain_manager | — | — |
| cisco | unified_communications_domain_manager | — | — |
| cisco | unified_communications_domain_manager_default_static | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x733-qw5x-37j6: Platform Software before 4
ghsa_unreviewed·2022-05-17
CVE-2015-4196 [MEDIUM] GHSA-x733-qw5x-37j6: Platform Software before 4
Platform Software before 4.4.5 in Cisco Unified Communications Domain Manager (CDM) 8.x has a hardcoded password for a privileged account, which allows remote attackers to obtain root access by leveraging knowledge of this password and entering it in an SSH session, aka Bug ID CSCuq45546.
Cisco
Cisco Unified Communications Domain Manager Default Static Privileged Account Credentials
vendor_cisco·2015-07-01·CVSS 10.0
CVE-2015-4196 [CRITICAL] CWE-264 Cisco Unified Communications Domain Manager Default Static Privileged Account Credentials
Cisco Unified Communications Domain Manager Default Static Privileged Account Credentials
A vulnerability in the Cisco Unified Communications Domain Manager Platform Software could allow an unauthenticated, remote attacker to login with the privileges of the root user and take full control of the affected system.
The vulnerability occurs because a privileged account has a default and static password. This account is created at installation and cannot be changed or deleted without impacting the functionality of the system. An attacker could exploit this vulnerability by remotely connecting to the affected system via SSH using this account. An exploit could allow the attacker to take full control over the affected system.
Cisco has released software updates that address this vulnerability
Cisco
Cisco Unified Communications Domain Manager Default Static Privileged Account Credentials
vendor_cisco
CVE-2015-4196 Cisco Unified Communications Domain Manager Default Static Privileged Account Credentials
CVE-2015-4196: Cisco Unified Communications Domain Manager Default Static Privileged Account Credentials
A vulnerability in the Cisco Unified Communications Domain Manager Platform Software could allow an unauthenticated, remote attacker to login with the privileges of the root user and take full control of the affected system. The vulnerability occurs because a privileged account has a default and static password. This account is created at installation and cannot be changed or deleted without impacting the functionality of the system. An attacker could exploit this vulnerability by remotely connecting to the affected system via SSH using this account. An exploit could allow the attacker to take full control over the affected system. Cisco has released software updates that address this v
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-07-04
Published