![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.106487 |
Category: | CISCO |
Title: | Cisco Intercloud Fabric Database Static Credentials Vulnerability (cisco-sa-20161221-icf) |
Summary: | A vulnerability in Cisco Intercloud Fabric for Business and; Cisco Intercloud Fabric for Providers could allow an unauthenticated, remote attacker to connect; to the database used by these products. |
Description: | Summary: A vulnerability in Cisco Intercloud Fabric for Business and Cisco Intercloud Fabric for Providers could allow an unauthenticated, remote attacker to connect to the database used by these products. Vulnerability Insight: The vulnerability occurs because the database account uses static credentials. Note that this database contains only internal objects used by the application. The database does not contain other credentials. Please note that this product has entered the end-of-sale and end-of-life process. Vulnerability Impact: An attacker could exploit this vulnerability by using these credentials to connect to the database. The contents of the database can then be examined or modified. Affected Software/OS: Cisco Intercloud Fabric versions 2.2.1, 2.3.1 and 3.1.1. Solution: See the referenced vendor advisory for a solution. CVSS Score: 6.5 CVSS Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2016-9217 BugTraq ID: 95023 http://www.securityfocus.com/bid/95023 |
Copyright | Copyright (C) 2016 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |