CVE-2016-1341
published 2016-02-24CVE-2016-1341: Cisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a blank root password, which allows local users to gain…
PriorityP347critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.08%
61.6th percentile
Cisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a blank root password, which allows local users to gain privileges via unspecified vectors, aka Bug ID CSCur22079.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nexus_2000_series_fabric_extender | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Nexus 2000 Series Fabric Extender Software Default Credential Vulnerability
vendor_cisco·2016-02-23·CVSS 6.9
CVE-2016-1341 [MEDIUM] CWE-287 Cisco Nexus 2000 Series Fabric Extender Software Default Credential Vulnerability
Cisco Nexus 2000 Series Fabric Extender Software Default Credential Vulnerability
A vulnerability in the Cisco Nexus 2000 Series Fabric Extender could allow an unauthenticated, local attacker to log in to the system shell with root user privileges.
The vulnerability is due to a missing password for the root user account on the affected system. This account is created at installation and cannot be changed or deleted without impacting the functionality of the system. An attacker could exploit this vulnerability by physically connecting to the affected system. An exploit could allow the attacker to access the system with root user privileges.
Cisco has not released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This adviso
Cisco
Cisco Nexus 2000 Series Fabric Extender Software Default Credential Vulnerability
vendor_cisco
CVE-2016-1341 Cisco Nexus 2000 Series Fabric Extender Software Default Credential Vulnerability
CVE-2016-1341: Cisco Nexus 2000 Series Fabric Extender Software Default Credential Vulnerability
A vulnerability in the Cisco Nexus 2000 Series Fabric Extender could allow an unauthenticated, local attacker to log in to the system shell with root user privileges. The vulnerability is due to a missing password for the root user account on the affected system. This account is created at installation and cannot be changed or deleted without impacting the functionality of the system. An attacker could exploit this vulnerability by physically connecting to the affected system. An exploit could allow the attacker to access the system with root user privileges. Cisco has not released software updates that address this vulnerability.
CWE: CWE-287, CWE-287
Bug IDs: CSCur22079
GHSA
GHSA-g2p3-wp5v-j757: Cisco NX-OS 7
ghsa_unreviewed·2022-05-17
CVE-2016-1341 [CRITICAL] GHSA-g2p3-wp5v-j757: Cisco NX-OS 7
Cisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a blank root password, which allows local users to gain privileges via unspecified vectors, aka Bug ID CSCur22079.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-02-24
Published