Ciena Navigator NCS and MCP Default Password Vulnerability in Hidden System Accounts
Vulnerability
A vulnerability exists in Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP) due to hidden system accounts used for internal operations. Some of these accounts have default passwords that could be easily guessed. Although these accounts have limited permissions individually, an attacker might exploit them in conjunction with other vulnerabilities to launch a more significant attack, potentially leading to unauthorized privilege escalation.
Impact
Exploitation of this vulnerability could allow an attacker to escalate privileges on the system by combining the use of these accounts with other vulnerabilities.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
