Cisco 's CDM Unified Software contains a privileged account with a static password .
Cisco Systems recently realized that its Unified Communications Domain Manager (Unified CDM) software includes a default privileged account with a static password that cannot be changed, thus exposing the platform to remote hacking.
Unified CDM is part of the Hosted Collaboration System and provides automation and management functions for Unifies CDM, Unity Connection, and Jabber applications, associated with phones and software clients.
The privileged account is created when Unified CDM is first installed and cannot be modified or removed without affecting system functionality. Cisco does not state exactly how this happens in its report, the only solution according to the company is to install the fixes it has released.
If the hole remains open, the intruders could gain access to the platform via SSH and log in with the default account that has root privileges. Such a thing would give them full control of the system.
Cisco rated the vulnerability with the maximum severity -10-, according to the Common Vulnerability Scoring System ( CVSS ) , which means that the hole is very easy to exploit and could lead to complete surrender of control of the system .
The vulnerability was fixed in software versions 4.4.5 and 4.4.4, but other hotfixes are also available for contract customers.
The hot issue was identified by the company during internal security testing and there is no information that proves the vulnerability has been identified and exploited ever so far.
