A default configuration allows full admin access to unauthenticated attackers.
https://threatpost.com/critical-unpatched-cisco-flaw/141010/