Vulnerability Name: | CVE-2009-0620 (CCN-48911) | ||||||||
Assigned: | 2009-02-25 | ||||||||
Published: | 2009-02-25 | ||||||||
Updated: | 2009-02-27 | ||||||||
Summary: | Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.1) uses default (1) usernames and (2) passwords for (a) the administrator and (b) web management, which makes it easier for remote attackers to perform configuration changes or obtain operating-system access. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
7.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-255 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-0620 Source: CISCO Type: Vendor Advisory 20090225 Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine Source: CCN Type: cisco-sa-20090225-ace Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine Source: CCN Type: OSVDB ID: 52382 Cisco ACE 4710 Application Control Engine Module for Routers Multiple Default Accounts Source: CCN Type: OSVDB ID: 52383 Cisco ACE Application Control Engine Appliance Multiple Default Accounts Source: BID Type: UNKNOWN 33900 Source: CCN Type: BID-33900 Multiple Cisco ACE Products Multiple Remote Vulnerabilities Source: XF Type: UNKNOWN cisco-acemodule-default-accounts(48911) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |