CVE-2018-15427
Published on: 10/05/2018 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:24:26 PM UTC
Certain versions of Connected Safety And Security Ucs C220 from Cisco contain the following vulnerability:
A vulnerability in Cisco Video Surveillance Manager (VSM) Software running on certain Cisco Connected Safety and Security Unified Computing System (UCS) platforms could allow an unauthenticated, remote attacker to log in to an affected system by using the root account, which has default, static user credentials. The vulnerability is due to the presence of undocumented, default, static user credentials for the root account of the affected software on certain systems. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and execute arbitrary commands as the root user.
- CVE-2018-15427 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
- Affected Vendor/Software:
Cisco - Cisco Video Surveillance Manager version n/a
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 10 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Cisco Video Surveillance Manager Default User Account Lets Remote Users Access the Target System - SecurityTracker | Third Party Advisory VDB Entry www.securitytracker.com text/html |
![]() |
Cisco Video Surveillance Manager Appliance Default Password Vulnerability | Vendor Advisory tools.cisco.com text/html |
![]() |
Cisco Video Surveillance Manager Appliance CVE-2018-15427 Insecure Default Password Vulnerability | Third Party Advisory VDB Entry cve.report (archive) text/html |
![]() |
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Cisco | Connected Safety And Security Ucs C220 | - | All | All | All |
Hardware
| Cisco | Connected Safety And Security Ucs C220 | - | All | All | All |
Hardware
| Cisco | Connected Safety And Security Ucs C220 | - | All | All | All |
Hardware
| Cisco | Connected Safety And Security Ucs C220 | - | All | All | All |
Hardware
| Cisco | Connected Safety And Security Ucs C220 | - | All | All | All |
Hardware
| Cisco | Connected Safety And Security Ucs C220 | - | All | All | All |
Hardware
| Cisco | Connected Safety And Security Ucs C220 | - | All | All | All |
Hardware
| Cisco | Connected Safety And Security Ucs C220 | - | All | All | All |
Application | Cisco | Video Surveillance Manager | 7.10 | All | All | All |
Application | Cisco | Video Surveillance Manager | 7.11 | All | All | All |
Application | Cisco | Video Surveillance Manager | 7.11.1 | All | All | All |
Application | Cisco | Video Surveillance Manager | 7.10 | All | All | All |
Application | Cisco | Video Surveillance Manager | 7.11 | All | All | All |
Application | Cisco | Video Surveillance Manager | 7.11.1 | All | All | All |
- cpe:2.3:h:cisco:connected_safety_and_security_ucs_c220:-:*:*:*:*:*:m4_1-ru:*:
- cpe:2.3:h:cisco:connected_safety_and_security_ucs_c220:-:*:*:*:*:*:m4_2-ru:*:
- cpe:2.3:h:cisco:connected_safety_and_security_ucs_c220:-:*:*:*:*:*:m5_1-ru:*:
- cpe:2.3:h:cisco:connected_safety_and_security_ucs_c220:-:*:*:*:*:*:m5_2-ru:*:
- cpe:2.3:h:cisco:connected_safety_and_security_ucs_c220:-:*:*:*:*:*:m4_1-ru:*:
- cpe:2.3:h:cisco:connected_safety_and_security_ucs_c220:-:*:*:*:*:*:m4_2-ru:*:
- cpe:2.3:h:cisco:connected_safety_and_security_ucs_c220:-:*:*:*:*:*:m5_1-ru:*:
- cpe:2.3:h:cisco:connected_safety_and_security_ucs_c220:-:*:*:*:*:*:m5_2-ru:*:
- cpe:2.3:a:cisco:video_surveillance_manager:7.10:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:video_surveillance_manager:7.11:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:video_surveillance_manager:7.11.1:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:video_surveillance_manager:7.10:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:video_surveillance_manager:7.11:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:video_surveillance_manager:7.11.1:*:*:*:*:*:*:*: