A vulnerability in Cisco SD-WAN Solution Software could...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jun 1, 2023
Description
Published by the National Vulnerability Database
Jul 16, 2020
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jun 1, 2023
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a default, static password. This account has root privileges. The vulnerability exists because the affected software has a user account with a default, static password. An attacker could exploit this vulnerability by remotely connecting to an affected system by using this account. A successful exploit could allow the attacker to log in by using this account with root privileges.
References