VYPR
Unrated severityNVD Advisory· Published Aug 26, 2020· Updated Nov 13, 2024

Cisco vWAAS for Cisco ENCS 5400-W Series and CSP 5000-W Series Default Credentials Vulnerability

CVE-2020-3446

Description

A vulnerability in Cisco Virtual Wide Area Application Services (vWAAS) with Cisco Enterprise NFV Infrastructure Software (NFVIS)-bundled images for Cisco ENCS 5400-W Series and CSP 5000-W Series appliances could allow an unauthenticated, remote attacker to log into the NFVIS CLI of an affected device by using accounts that have a default, static password. The vulnerability exists because the affected software has user accounts with default, static passwords. An attacker with access to the NFVIS CLI of an affected device could exploit this vulnerability by logging into the CLI. A successful exploit could allow the attacker to access the NFVIS CLI with administrator privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cisco vWAAS for ENCS 5400-W and CSP 5000-W series appliances contain default static passwords allowing unauthenticated remote attackers to gain admin CLI access.

Vulnerability

Cisco Virtual Wide Area Application Services (vWAAS) with Cisco Enterprise NFV Infrastructure Software (NFVIS)-bundled images for Cisco ENCS 5400-W Series and CSP 5000-W Series appliances contain user accounts that have default, static passwords. This vulnerability affects all versions of the software prior to the fixed releases provided in the Cisco advisory [1]. The default credentials are present in the NFVIS CLI, allowing unauthenticated access.

Exploitation

An unauthenticated, remote attacker can exploit this vulnerability by connecting to the NFVIS CLI of an affected device and logging in using the default, static passwords. No prior authentication or user interaction is required. The attacker only needs network access to the management interface of the appliance.

Impact

Successful exploitation grants the attacker administrator privileges on the NFVIS CLI. With these privileges, the attacker can fully compromise the NFVIS system, potentially affecting hosted services and gaining persistent access to the appliance.

Mitigation

Cisco has released free software updates that address this vulnerability. Customers should upgrade to the fixed versions as specified in the Cisco Security Advisory [1]. No workarounds are available. This vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.