Preview Tool

Cisco Bug: CSCuq45546 - CUCDM Default Static Privileged Account Credentials

Last Modified

Feb 12, 2018

Products (1)

  • Cisco Hosted Collaboration Solution (HCS)

Known Affected Releases

4.4(3) 8.1(4)ER2

Description (partial)

A vulnerability in the Cisco Unified Communications Domain Manager Platform Software could allow an unauthenticated, remote attacker to login
with the privileges of the root user and take full control of the affected system.

The vulnerability occurs because a privileged account has a default and static password. This account is created at installation and cannot be
changed or deleted without impacting the functionality of the system. An attacker could exploit this vulnerability by remotely connecting to the
affected system via SSH using this account. An exploit could allow the attacker to take full control over the affected system.

Cisco has released free software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available. This
advisory is available at the following link:

See published Cisco Security Advisory
Bug details contain sensitive information and therefore require a account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.