Use of hardcoded credentials in Cisco Network Assurance - CVE-2019-1688
Published: February 12, 2019
Cisco Network Assurance
Detailed vulnerability description
The vulnerability allows a local unauthenticated attacker to obtain potentially sensitive information or cause DoS condition.
The vulnerability exists in the management web interface of Cisco Network Assurance Engine (NAE) due to a fault in the password management system of NAE. A local attacker can authenticate with the default administrator password via the CLI to view potentially sensitive information or bring the server down, causing a DoS condition.