CVE-2016-1329

CRITICAL

Cisco NX-OS <6.0(2)U6(5)-<6.0(2)A7(1) - Privilege Escalation

Title source: llm

Description

Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardcoded credentials, which allows remote attackers to obtain root privileges via a (1) TELNET or (2) SSH session, aka Bug ID CSCuy25800.

Scores

CVSS v3 9.8
EPSS 0.0207
EPSS Percentile 83.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-287
Status draft

Affected Products (4)

samsung/x14j_firmware
sun/opensolaris
zyxel/gs1900-10hp_firmware < 2.50\(aazi.0\)c0
zzinc/keymouse_firmware

Timeline

Published Mar 03, 2016
Tracked Since Feb 18, 2026