SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   Device (Router/Bridge/Hub)  >   Cisco NX-OS Vendors:   Cisco
Cisco Nexus 2000 Series Fabric Extender Missing Password Lets Local Users Obtain Root Privileges
SecurityTracker Alert ID:  1035088
SecurityTracker URL:  http://securitytracker.com/id/1035088
CVE Reference:   CVE-2016-1341   (Links to External Site)
Date:  Feb 24 2016
Impact:   Root access via local system
Vendor Confirmed:  Yes  Exploit Included:  Yes  

Description:   A vulnerability was reported in Cisco Nexus 2000 Series Fabric Extenders. A local user can obtain root privileges on the target system.

The root user account does not have a password. A physically local user can access the system shell with root privileges.

The account is created during installation and cannot be changed or deleted.

Cisco Nexus 2000 Series Fabric Extenders are affected.

The vendor has assigned bug ID CSCur22079 to this vulnerability.

Impact:   A physically local user can obtain root privileges on the target system.
Solution:   No solution was available at the time of this entry.

The vendor's advisory is available at:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160223-nx2000

Vendor URL:  tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160223-nx2000 (Links to External Site)
Cause:   Authentication error

Message History:   None.


 Source Message Contents



[Original Message Not Available for Viewing]


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2020, SecurityGlobal.net LLC