ID

VAR-201608-0497


TITLE

Cisco EPC3925 UPC Unsecure Default Password Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2016-06943

DESCRIPTION

The CiscoEPC3925 is a home router device. The CiscoEPC3925UPC has an insecure default password vulnerability. Knowledge of remote attackers with default credentials may exploit this vulnerability to gain unauthorized access and perform unauthorized actions. This may aid in further attacks

Trust: 0.81

sources: CNVD: CNVD-2016-06943 // BID: 92128

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-06943

AFFECTED PRODUCTS

vendor:ciscomodel:epc3925 esip-12-v302r125573-scope: - version: -

Trust: 0.6

vendor:ciscomodel:epc3925 upc esip-12-v302r125573-scope: - version: -

Trust: 0.3

sources: CNVD: CNVD-2016-06943 // BID: 92128

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2016-06943
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2016-06943
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2016-06943

THREAT TYPE

network

Trust: 0.3

sources: BID: 92128

TYPE

Design Error

Trust: 0.3

sources: BID: 92128

PATCH

title:CiscoEPC3925UPC Unsafe Default Password Vulnerability Patchurl:https://www.cnvd.org.cn/patchinfo/show/80954

Trust: 0.6

sources: CNVD: CNVD-2016-06943

EXTERNAL IDS

db:BIDid:92128

Trust: 0.9

db:CNVDid:CNVD-2016-06943

Trust: 0.6

sources: CNVD: CNVD-2016-06943 // BID: 92128

REFERENCES

url:http://seclists.org/bugtraq/2016/jul/88

Trust: 0.9

url:http://www.securityfocus.com/bid/92128/

Trust: 0.6

url:https://github.com/ebux/cable-modems/tree/master/cisco

Trust: 0.3

url:http://www.cisco.com/

Trust: 0.3

sources: CNVD: CNVD-2016-06943 // BID: 92128

CREDITS

Gergely Eberhardt from SEARCH-LAB Ltd.

Trust: 0.3

sources: BID: 92128

SOURCES

db:CNVDid:CNVD-2016-06943
db:BIDid:92128

LAST UPDATE DATE

2022-05-17T01:43:18.510000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-06943date:2016-08-31T00:00:00
db:BIDid:92128date:2016-07-20T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-06943date:2016-08-31T00:00:00
db:BIDid:92128date:2016-07-20T00:00:00