CVE-2007-2282
Summary
| CVE | CVE-2007-2282 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-04-26 19:19:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Cisco Network Services (CNS) NetFlow Collection Engine (NFC) before 6.0 has an nfcuser account with the default password nfcuser, which allows remote attackers to modify the product configuration and, when installed on Linux, obtain login access to the host operating system. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Netflow Collection Engine | 1.0 | All | All | All |
| Application | Cisco | Netflow Collection Engine | 2.0 | All | All | All |
| Application | Cisco | Netflow Collection Engine | 3.0 | All | All | All |
| Application | Cisco | Netflow Collection Engine | 3.5 | All | All | All |
| Application | Cisco | Netflow Collection Engine | 3.6 | All | All | All |
| Application | Cisco | Netflow Collection Engine | 4.0 | All | All | All |
| Application | Cisco | Netflow Collection Engine | 5.0 | All | All | All |
| Application | Cisco | Netflow Collection Engine | 5.0.3 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| US-CERT Vulnerability Notes | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| www.osvdb.org/35524 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| SecurityTracker.com Archives - Cisco NetFlow Collection Engine Default Passwords Let Remote Users Access the System | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Cisco NetFlow Collection Engine Remote Default Account Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Cisco Security Advisory: Default Passwords in NetFlow Collection Engine [Products & Services] - Cisco Systems | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.