Language:
Severity: Critical
ID: 23938
File Name: cisco_default_pw.nasl
Version: 1.50
Type: remote
Family: CISCO
Published: 12/23/2006
Updated: 11/27/2023
Supported Sensors: Nessus
CVSS Score Rationale: Av:n is justified since the plugin tries to login via ssh or telnet. while the nvd score implies the the device is only accessible locally, that's not explicitly specified in the cve description: an account on a router, firewall, or other network device has a default, null, blank, or missing password. it is a reasonable assumption that if the plugin can log in with one of the sets of credentials attempted in the plugin, it can own the device (hence cia complete instead of partial).
Risk Factor: Medium
Score: 6.7
Risk Factor: Critical
Base Score: 10
Temporal Score: 7.7
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
CVSS Score Source: CVE-1999-0508
Risk Factor: Critical
Base Score: 9.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:/o:cisco
Excluded KB Items: global_settings/supplied_logins_only
Exploit Ease: No exploit is required
Vulnerability Publication Date: 1/1/1999
CVE: CVE-1999-0508