First published: Thu Apr 11 2013(Updated: )
The Cisco Prime Network Control System (NCS) appliance with software before 1.1.1.24 has a default password for the database user account, which makes it easier for remote attackers to change the configuration or cause a denial of service (service disruption) via unspecified vectors, aka Bug ID CSCtz30468.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Network Control System | =1.1 | |
Cisco Prime Network Control System Software |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1170 has a high severity rating due to the risk of unauthorized access and potential service disruption.
To fix CVE-2013-1170, update to Cisco Prime Network Control System software version 1.1.1.24 or later.
CVE-2013-1170 affects Cisco Prime Network Control System versions prior to 1.1.1.24.
The risks include unauthorized configuration changes and denial of service attacks by exploiting the default database password.
Yes, it is recommended to change the default password for the database user account as a temporary measure.