Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.106487
Category:CISCO
Title:Cisco Intercloud Fabric Database Static Credentials Vulnerability (cisco-sa-20161221-icf)
Summary:A vulnerability in Cisco Intercloud Fabric for Business and; Cisco Intercloud Fabric for Providers could allow an unauthenticated, remote attacker to connect; to the database used by these products.
Description:Summary:
A vulnerability in Cisco Intercloud Fabric for Business and
Cisco Intercloud Fabric for Providers could allow an unauthenticated, remote attacker to connect
to the database used by these products.

Vulnerability Insight:
The vulnerability occurs because the database account uses
static credentials.

Note that this database contains only internal objects used by the application. The database does
not contain other credentials.

Please note that this product has entered the end-of-sale and end-of-life process.

Vulnerability Impact:
An attacker could exploit this vulnerability by using these
credentials to connect to the database. The contents of the database can then be examined or
modified.

Affected Software/OS:
Cisco Intercloud Fabric versions 2.2.1, 2.3.1 and 3.1.1.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
6.5

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-9217
BugTraq ID: 95023
http://www.securityfocus.com/bid/95023
CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.