CVE-2013-1170: High severity cisco prime network control system vulnerability
The Cisco Prime Network Control System (NCS) appliance with software before 1.1.1.24 has a default password for the database user account, which makes it easier for remote attackers to change the configuration or cause a denial of service (service disruption) via unspecified vectors, aka Bug ID CSCtz30468.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1170?
CVE-2013-1170 has a high severity rating due to the risk of unauthorized access and potential service disruption.
How do I fix CVE-2013-1170?
To fix CVE-2013-1170, update to Cisco Prime Network Control System software version 1.1.1.24 or later.
What types of systems are affected by CVE-2013-1170?
CVE-2013-1170 affects Cisco Prime Network Control System versions prior to 1.1.1.24.
What are the risks associated with CVE-2013-1170?
The risks include unauthorized configuration changes and denial of service attacks by exploiting the default database password.
Is there a workaround for CVE-2013-1170?
Yes, it is recommended to change the default password for the database user account as a temporary measure.