===================================================================== CERT-Renater Note d'Information No. 2013/VULN146 _____________________________________________________________________ DATE : 11/04/2013 HARDWARE PLATFORM(S): Cisco Prime Network Control System NCS appliances. OPERATING SYSTEM(S):Cisco Prime NCS software versions prior to 1.1.1.24. ====================================================================== http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130410-ncs ______________________________________________________________________ Cisco Security Advisory: Cisco Prime Network Control Systems Database Default Credentials Vulnerability Advisory ID: cisco-sa-20130410-ncs Revision 1.0 For Public Release 2013 April 10 16:00 UTC (GMT) +---------------------------------------------------------------------- Summary ======= Cisco Prime Network Control System NCS appliances that are running software versions prior to 1.1.1.24 contain a database user account that is created with default credentials. An attacker could use this account to modify the configuration of the application or disrupt services. A software upgrade is required to resolve this vulnerability. Cisco has released free software updates that address this vulnerability. There is no workaround for this vulnerability. This advisory is available at the following link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130410-ncs ====================================================================== ========================================================= Serveur de référence du CERT-Renater https://services.renater.fr/ssi/ ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23 - 25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email: certsvp@renater.fr + =========================================================