{"api_version":"1","generated_at":"2026-07-23T06:18:28+00:00","cve":"CVE-2007-2282","urls":{"html":"https://cve.report/CVE-2007-2282","api":"https://cve.report/api/cve/CVE-2007-2282.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-2282","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-2282"},"summary":{"title":"CVE-2007-2282","description":"Cisco Network Services (CNS) NetFlow Collection Engine (NFC) before 6.0 has an nfcuser account with the default password nfcuser, which allows remote attackers to modify the product configuration and, when installed on Linux, obtain login access to the host operating system.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-04-26 19:19:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2007/1545","name":"http://www.vupen.com/english/advisories/2007/1545","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/127545","name":"http://www.kb.cert.org/vuls/id/127545","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Notes","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/35524","name":"http://www.osvdb.org/35524","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://securitytracker.com/id?1017960","name":"http://securitytracker.com/id?1017960","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Cisco NetFlow Collection Engine Default Passwords Let Remote Users Access the System","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/23647","name":"http://www.securityfocus.com/bid/23647","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cisco NetFlow Collection Engine Remote Default Account Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33861","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33861","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.cisco.com/en/US/products/products_security_advisory09186a008082c520.shtml","name":"http://www.cisco.com/en/US/products/products_security_advisory09186a008082c520.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Cisco Security Advisory: Default Passwords in NetFlow Collection Engine  [Products & Services] - Cisco Systems","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-2282","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-2282","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"2282","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"netflow_collection_engine","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2282","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"netflow_collection_engine","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2282","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"netflow_collection_engine","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2282","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"netflow_collection_engine","cpe6":"3.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2282","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"netflow_collection_engine","cpe6":"3.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2282","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"netflow_collection_engine","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2282","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"netflow_collection_engine","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2282","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"netflow_collection_engine","cpe6":"5.0.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T13:33:28.228Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2007-1545","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/1545"},{"name":"20070425 Default Passwords in NetFlow Collection Engine","tags":["vendor-advisory","x_refsource_CISCO","x_transferred"],"url":"http://www.cisco.com/en/US/products/products_security_advisory09186a008082c520.shtml"},{"name":"35524","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/35524"},{"name":"23647","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/23647"},{"name":"1017960","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1017960"},{"name":"cisco-nfc-default-password(33861)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33861"},{"name":"VU#127545","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/127545"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-04-25T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cisco Network Services (CNS) NetFlow Collection Engine (NFC) before 6.0 has an nfcuser account with the default password nfcuser, which allows remote attackers to modify the product configuration and, when installed on Linux, obtain login access to the host operating system."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2007-1545","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/1545"},{"name":"20070425 Default Passwords in NetFlow Collection Engine","tags":["vendor-advisory","x_refsource_CISCO"],"url":"http://www.cisco.com/en/US/products/products_security_advisory09186a008082c520.shtml"},{"name":"35524","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/35524"},{"name":"23647","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/23647"},{"name":"1017960","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1017960"},{"name":"cisco-nfc-default-password(33861)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33861"},{"name":"VU#127545","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/127545"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-2282","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cisco Network Services (CNS) NetFlow Collection Engine (NFC) before 6.0 has an nfcuser account with the default password nfcuser, which allows remote attackers to modify the product configuration and, when installed on Linux, obtain login access to the host operating system."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2007-1545","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/1545"},{"name":"20070425 Default Passwords in NetFlow Collection Engine","refsource":"CISCO","url":"http://www.cisco.com/en/US/products/products_security_advisory09186a008082c520.shtml"},{"name":"35524","refsource":"OSVDB","url":"http://www.osvdb.org/35524"},{"name":"23647","refsource":"BID","url":"http://www.securityfocus.com/bid/23647"},{"name":"1017960","refsource":"SECTRACK","url":"http://securitytracker.com/id?1017960"},{"name":"cisco-nfc-default-password(33861)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33861"},{"name":"VU#127545","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/127545"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-2282","datePublished":"2007-04-26T19:00:00.000Z","dateReserved":"2007-04-26T00:00:00.000Z","dateUpdated":"2024-08-07T13:33:28.228Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-04-26 19:19:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:netflow_collection_engine:1.0:*:*:*:*:*:*:*","matchCriteriaId":"1807D723-161A-46FD-9AD7-F7C69D0A8413"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:netflow_collection_engine:2.0:*:*:*:*:*:*:*","matchCriteriaId":"6B221905-FA88-42E4-AD14-46C898BD2F28"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:netflow_collection_engine:3.0:*:*:*:*:*:*:*","matchCriteriaId":"D8E52AEC-B8E0-42F3-B856-C1057E7C45F3"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:netflow_collection_engine:3.5:*:*:*:*:*:*:*","matchCriteriaId":"B886D5FF-14E2-49BB-9E7A-CA4A4856012B"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:netflow_collection_engine:3.6:*:*:*:*:*:*:*","matchCriteriaId":"98F41DD9-70BA-443F-8A77-5DADC03E03D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:netflow_collection_engine:4.0:*:*:*:*:*:*:*","matchCriteriaId":"4853160D-497B-48CA-AA86-CA58C9893D0B"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:netflow_collection_engine:5.0:*:*:*:*:*:*:*","matchCriteriaId":"3BB06510-5A6C-4360-9362-62F1EAA52C94"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:netflow_collection_engine:5.0.3:*:*:*:*:*:*:*","matchCriteriaId":"CC215FF5-586D-483E-A53A-D2057AA7A18B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"2282","Ordinal":"1","Title":"CVE-2007-2282","CVE":"CVE-2007-2282","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"2282","Ordinal":"1","NoteData":"Cisco Network Services (CNS) NetFlow Collection Engine (NFC) before 6.0 has an nfcuser account with the default password nfcuser, which allows remote attackers to modify the product configuration and, when installed on Linux, obtain login access to the host operating system.","Type":"Description","Title":"CVE-2007-2282"},{"CveYear":"2007","CveId":"2282","Ordinal":"2","NoteData":"2007-04-26","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"2282","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}