Cisco has published an advisory that discloses a vulnerability in the Video Surveillance Manager appliance that could allow unauthenticated attackers to gain root access using default, static credentials.
The security issue occurs due to unauthorized default root account credentials remaining enabled after the software is installed by Cisco.
Furthermore, when successfully exploited, the vulnerability gives attackers access to run any command as the root user
The vulnerability affects the pre-installed Cisco Video Surveillance Manager (VSM) software, versions 7.10, 7.11, and 7.11.1, available on certain UCS (Unified Computing Safety) and Cisco Connected Unified Computing System (UCS) wireless security platforms, and allows remote attackers to log in using user credentials as the root account.
Additionally, the affected UCS platforms are CPS-UCSM4-1RU-K9, CPS-UCSM4-2RU-K9, KIN-UCSM5-1RU-K9, and KIN-UCSM5-2RU-K9.
Cisco has already released security updates for all vulnerabilities described in the pre-defined password vulnerability advisory
The system manages whether Cisco's VSM software is installed and running on its UCS platforms, you can check this by selecting the Model field in the System Settings > Server > General tab after logging in to the Cisco Video Surveillance Operations Manager software.
According to Cisco, there are no known solutions that would help users of Cisco Video Surveillance Manager (VSM) software mitigate the problem.
The company announced that it has already released a security update that affects VSM software running on vulnerable UCS.
All customers with licenses for the software and platforms considered vulnerable are advised to upgrade and are also encouraged to contact the Cisco Technical Assistance Center (TAC) or Cisco maintenance providers for more details.

