SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   Device (Embedded Server/Appliance)  >   Cisco Prime Network Control System Vendors:   Cisco
Cisco Prime Network Control System Default Credentials Let Remote Users Modify the Configuration
SecurityTracker Alert ID:  1028419
SecurityTracker URL:  http://securitytracker.com/id/1028419
CVE Reference:   CVE-2013-1170   (Links to External Site)
Updated:  Jul 4 2013
Original Entry Date:  Apr 10 2013
Impact:   Modification of system information
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): prior to 1.1.1.24
Description:   A vulnerability was reported in Cisco Prime Network Control System. A remote user can modify the configuration settings.

Cisco Prime Network Control System (NCS) uses common default credentials for the database user. A remote user can modify the configuration settings of the target device.

Cisco has assigned Cisco bug IDs CSCtz30468 and CSCub54624 to this vulnerability.

Erik Parker of Amazon reported this vulnerability.

Impact:   A remote user can modify the configuration settings.
Solution:   The vendor has issued a fix (1.1.1.24).

The vendor's advisories are available at:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130410-ncs
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1170

Vendor URL:  tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130410-ncs (Links to External Site)
Cause:   Configuration error

Message History:   None.


 Source Message Contents

Subject:  Cisco Security Advisory: Cisco Prime Network Control Systems Database Default Credentials Vulnerability

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Cisco Security Advisory: Cisco Prime Network Control Systems Database
Default Credentials Vulnerability

Advisory ID: cisco-sa-20130410-ncs

Revision 1.0

For Public Release 2013 April 10 16:00  UTC (GMT)

+----------------------------------------------------------------------

Summary
=======

Cisco Prime Network Control System NCS appliances that are running
software versions prior to 1.1.1.24 contain a database user account that
is created with default credentials. An attacker could use this account
to modify the configuration of the application or disrupt services.

A software upgrade is required to resolve this vulnerability.

Cisco has released free software updates that address this
vulnerability. There is no workaround for this vulnerability.

This advisory is available at the following link:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130410-ncs

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iF4EAREIAAYFAlFlkSkACgkQUddfH3/BbTrRtQEAjKEfrZ4g2yWNSGLKq4eYQtGy
+N+7Dea/oX5EQtOnnqEA/3h6A5A+RsvGrcVAse061dKJCwT0X2q3khD437CqSYZy
=TLJ/
-----END PGP SIGNATURE-----
_______________________________________________
cust-security-announce mailing list
cust-security-announce@cisco.com
To unsubscribe, send the command "unsubscribe" in the subject of your message to cust-security-announce-leave@cisco.com
 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2021, SecurityGlobal.net LLC