CVE-2016-1341Improper Authentication in Cisco Nx-os

Severity
9.8CRITICALNVD
EPSS
0.3%
top 48.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 24
Latest updateMay 17

Description

Cisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a blank root password, which allows local users to gain privileges via unspecified vectors, aka Bug ID CSCur22079.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDcisco/nx-os7.0\(1\)n1\(1\), 7.0\(1\)n1\(3\), 7.0\(4\)n1\(1\)+2

🔴Vulnerability Details

2
GHSA
GHSA-g2p3-wp5v-j757: Cisco NX-OS 72022-05-17
CVEList
CVE-2016-1341: Cisco NX-OS 72016-02-24

📋Vendor Advisories

1
Cisco
Cisco Nexus 2000 Series Fabric Extender Software Default Credential Vulnerability2016-02-23
CVE-2016-1341 — Improper Authentication in Cisco Nx-os | cvebase