Vulnslist

find the latest Cisco vulnerabilities

Default Passwords in NetFlow Collection Engine

cisco-sa-20070425-nfc · Medium · Published · Updated

Versions of Cisco Network Services (CNS) NetFlow Collection Engine (NFC) prior to 6.0 create and use default accounts with identical usernames and passwords. An attacker with knowledge of these accounts can modify the application configuration and, in certain instances, gain user access to the host operating system. The upgrade to NFC version 6.0 is not a free upgrade. This default password issue does not require a software upgrade and can be changed by a configuration command for all affected customers. The workaround detailed in this document demonstrates how to change the passwords in 5.0. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20070425-nfc.

Workarounds

No workaround information imported yet.

CVEsCVE-2007-2282
Cisco Bug IDsNA
CVSS ScoreBase 5.6
Product Names From Source
Cisco NetFlow Collection Engine

Related Products

Product CVE Evidence
Cisco RV Series Routers CVE-2007-2282 Cisco OpenVuln
Cisco Nexus Dashboard CVE-2007-2282 Cisco OpenVuln
Cisco NetFlow Collection Engine CVE-2007-2282 Cisco OpenVuln