CVE-2020-3446 (CNNVD-202008-954)
中文标题:
Cisco ENCS 5400-W Series和CSP 5000-W Series 信任管理问题漏洞
英文标题:
Cisco vWAAS for Cisco ENCS 5400-W Series and CSP 5000-W Series Default Credentials Vulnerability
漏洞描述
中文描述:
Cisco Enterprise NFV Infrastructure Software(NFVIS)是美国思科(Cisco)公司的一套NVF基础架构软件平台。该平台可以通过中央协调器和控制器实现虚拟化服务的全生命周期管理。 Cisco ENCS 5400-W Series和CSP 5000-W Series中的Virtual Wide Area Application Services (vWAAS)(带有NFVIS捆绑的镜像)存在信任管理问题漏洞,该漏洞源于用户账户使用了默认的静态密码。攻击者可借助该漏洞利用该漏洞登录到NFVIS CLI中。
英文描述:
A vulnerability in Cisco Virtual Wide Area Application Services (vWAAS) with Cisco Enterprise NFV Infrastructure Software (NFVIS)-bundled images for Cisco ENCS 5400-W Series and CSP 5000-W Series appliances could allow an unauthenticated, remote attacker to log into the NFVIS CLI of an affected device by using accounts that have a default, static password. The vulnerability exists because the affected software has user accounts with default, static passwords. An attacker with access to the NFVIS CLI of an affected device could exploit this vulnerability by logging into the CLI. A successful exploit could allow the attacker to access the NFVIS CLI with administrator privileges.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco Wide Area Application Services (WAAS) | n/a | - | - |
cpe:2.3:a:cisco:cisco_wide_area_application_services_(waas):n_a:*:*:*:*:*:*:*
|
| cisco | encs_5406-w_firmware | 6.4\(1\) | - | - |
cpe:2.3:o:cisco:encs_5406-w_firmware:6.4\(1\):*:*:*:*:*:*:*
|
| cisco | encs_5406-w_firmware | 6.4\(3d\) | - | - |
cpe:2.3:o:cisco:encs_5406-w_firmware:6.4\(3d\):*:*:*:*:*:*:*
|
| cisco | encs_5408-w_firmware | 6.4\(1\) | - | - |
cpe:2.3:o:cisco:encs_5408-w_firmware:6.4\(1\):*:*:*:*:*:*:*
|
| cisco | encs_5408-w_firmware | 6.4\(3d\) | - | - |
cpe:2.3:o:cisco:encs_5408-w_firmware:6.4\(3d\):*:*:*:*:*:*:*
|
| cisco | encs_5412-w_firmware | 6.4\(1\) | - | - |
cpe:2.3:o:cisco:encs_5412-w_firmware:6.4\(1\):*:*:*:*:*:*:*
|
| cisco | encs_5412-w_firmware | 6.4\(3d\) | - | - |
cpe:2.3:o:cisco:encs_5412-w_firmware:6.4\(3d\):*:*:*:*:*:*:*
|
| cisco | csp_5228-w_firmware | 6.4\(1\) | - | - |
cpe:2.3:o:cisco:csp_5228-w_firmware:6.4\(1\):*:*:*:*:*:*:*
|
| cisco | csp_5228-w_firmware | 6.4\(3d\) | - | - |
cpe:2.3:o:cisco:csp_5228-w_firmware:6.4\(3d\):*:*:*:*:*:*:*
|
| cisco | csp_5436-w_firmware | 6.4\(1\) | - | - |
cpe:2.3:o:cisco:csp_5436-w_firmware:6.4\(1\):*:*:*:*:*:*:*
|
| cisco | csp_5436-w_firmware | 6.4\(3d\) | - | - |
cpe:2.3:o:cisco:csp_5436-w_firmware:6.4\(3d\):*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
3.0 (cna)
CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2020-3446 |
2025-11-11 15:20:37 | 2025-11-11 07:36:19 |
| NVD | nvd_CVE-2020-3446 |
2025-11-11 14:57:02 | 2025-11-11 07:44:43 |
| CNNVD | cnnvd_CNNVD-202008-954 |
2025-11-11 15:10:29 | 2025-11-11 07:56:25 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 信任管理问题
- cnnvd_id: 未提取 -> CNNVD-202008-954
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 11
- data_sources: ['cve'] -> ['cve', 'nvd']