Vulnerabilities > CVE-2011-0354 - Credentials Management vulnerability in Cisco products

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
cisco
CWE-255
critical
exploit available

Summary

The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with software before TC4.0.0 has a blank password for the root account, which makes it easier for remote attackers to obtain access via an unspecified login method.

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionTandberg E & EX & C Series Endpoints - Default Credentials for Root Account. CVE-2011-0354. Remote exploit for hardware platform
fileexploits/hardware/remote/16100.txt
idEDB-ID:16100
last seen2016-02-01
modified2011-02-02
platformhardware
port
published2011-02-02
reporterCisco Security
sourcehttps://www.exploit-db.com/download/16100/
titleTandberg E & EX & C Series Endpoints - Default Credentials for Root Account
typeremote

Seebug

bulletinFamilyexploit
descriptionNo description provided by source.
idSSV:70658
last seen2017-11-19
modified2014-07-01
published2014-07-01
reporterRoot
sourcehttps://www.seebug.org/vuldb/ssvid-70658
titleTandberg E, EX and C Series Endpoints Default Credentials for Root Account