CVE-2015-6389
published 2015-12-13CVE-2015-6389: Cisco Prime Collaboration Assurance before 11.0 has a hardcoded cmuser account, which allows remote attackers to obtain access by establishing an SSH session…
PriorityP350critical9CVSS 2.0
AVNACLAuNCPIPAC
EPSS
2.60%
83.5th percentile
Cisco Prime Collaboration Assurance before 11.0 has a hardcoded cmuser account, which allows remote attackers to obtain access by establishing an SSH session and leveraging knowledge of this account's password, aka Bug ID CSCus62707.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | prime_collaboration_assurance | — | — |
| cisco | prime_collaboration_assurance | — | — |
| cisco | prime_collaboration_assurance_default_account_credential | — | — |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:N/C:P/I:P/A:C
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Prime Collaboration Assurance Default Account Credential Vulnerability
vendor_cisco·2015-12-09·CVSS 9.0
CVE-2015-6389 [CRITICAL] CWE-287 Cisco Prime Collaboration Assurance Default Account Credential Vulnerability
Cisco Prime Collaboration Assurance Default Account Credential Vulnerability
A vulnerability in Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated, remote attacker to log in to the system shell with the default cmuser user account and access the shell with a limited set of permissions.
The vulnerability is due to an undocumented account that has a default and static password. This account is created during installation and cannot be changed or deleted without impacting the functionality of the system. The first time this account is used the system will request that the user change the default password.
An attacker could exploit this vulnerability by remotely connecting to the affected system via SSH by using the undocumented account. Successful exploitatio
Cisco
Cisco Prime Collaboration Assurance Default Account Credential Vulnerability
vendor_cisco
CVE-2015-6389 Cisco Prime Collaboration Assurance Default Account Credential Vulnerability
CVE-2015-6389: Cisco Prime Collaboration Assurance Default Account Credential Vulnerability
A vulnerability in Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated, remote attacker to log in to the system shell with the default cmuser user account and access the shell with a limited set of permissions. The vulnerability is due to an undocumented account that has a default and static password. This account is created during installation and cannot be changed or deleted without impacting the functionality of the system. The first time this account is used the system will request that the user change the default password. An attacker could exploit this vulnerability by remotely connecting to the affected system via SSH by using the undocumented account. Successful
GHSA
GHSA-36v9-qrwx-hfc8: Cisco Prime Collaboration Assurance before 11
ghsa_unreviewed·2022-05-17
CVE-2015-6389 [HIGH] CWE-287 GHSA-36v9-qrwx-hfc8: Cisco Prime Collaboration Assurance before 11
Cisco Prime Collaboration Assurance before 11.0 has a hardcoded cmuser account, which allows remote attackers to obtain access by establishing an SSH session and leveraging knowledge of this account's password, aka Bug ID CSCus62707.
No detection rules found.
No public exploits indexed.
Securelist
Threat intelligence report for the telecommunications industry
blogs_securelist·2016-08-22
Threat intelligence report for the telecommunications industry
Table of Contents
Introduction
Executive summary
Typical threats targeting telecoms
Overview
Threats directed at telecoms companies
DDoS
Targeted attacks
Unaddressed software vulnerabilities
The impact of service misconfiguration
Vulnerabilities in network devices
Malicious insiders
Threats targeting CSP/ISP subscribers
Overview
Social engineering, phishing and other ways in
Vulnerable kit
The risk of local cells
USIM card vulnerabilities
Conclusion
Authors
Kaspersky
Download PDF
## Introduction
The telecommunications industry keeps the world connected. Telecoms providers build, operate and manage the complex network infrastructures used for voice and data transmission – and they communicate and store vast amounts of sensitive data. This makes them a top target for c
Securelist
Threat intelligence report for the telecommunications industry
blogs_securelist·2016-08-22
Threat intelligence report for the telecommunications industry
Table of Contents
- Introduction
- Executive summary
- Typical threats targeting telecoms
- Conclusion
Authors
- Kaspersky
Download PDF
## Introduction
The telecommunications industry keeps the world connected. Telecoms providers build, operate and manage the complex network infrastructures used for voice and data transmission – and they communicate and store vast amounts of sensitive data. This makes them a top target for cyber-attack.
According to PwC’s Global State of Information Security, 2016, IT security incidents in the telecoms sector increased 45% in 2015 compared to the year before. Telecoms providers need to arm themselves against this growing risk.
In this intelligence report, we cover the main IT security threats facing the telecommunications industry and illustrate t
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-pcahttp://www.securityfocus.com/bid/78738http://www.securitytracker.com/id/1034361http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-pcahttp://www.securityfocus.com/bid/78738http://www.securitytracker.com/id/1034361
2015-12-13
Published