CVE-2016-1329

Severity
9.8CRITICAL
EPSS
2.1%
top 16.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 3
Latest updateMay 17

Description

Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardcoded credentials, which allows remote attackers to obtain root privileges via a (1) TELNET or (2) SSH session, aka Bug ID CSCuy25800.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

NVDzyxel/gs1900-10hp_firmware< 2.50\(aazi.0\)c0
NVDsun/opensolarissnv_124
NVDsamsung/x14j_firmwaret-ms14jakucb-1102.5

🔴Vulnerability Details

2
GHSA
GHSA-hcw6-7w4p-27j8: Cisco NX-OS 62022-05-17
CVEList
CVE-2016-1329: Cisco NX-OS 62016-03-03

📋Vendor Advisories

1
Cisco
Cisco Nexus 3000 Series and 3500 Platform Switches Insecure Default Credentials Vulnerability2016-03-03