Impact
Hidden internal system accounts are used by Ciena’s Navigator Network Control Suite, Manage Control Plan, and Planner Plus OnPrem and contain default compromised account with other weaknesses to perform a larger attack, potentially escalating privileges on the affected systems.
Affected Systems
The vulnerability affects Ciena products: Navigator NCS (versions earlier than 8.2 or 8.1-P02), Manage Control Plan (MCP) versions earlier than 8.0-P04 or 7.2-P07, and Planner Plus OnPrem versions earlier than 4.2 or 4.1-P01. These systems were identified by the CNA as vulnerable to the default password issue.
Risk and Exploitability
The flaw carries a CVSS score of 9.8 and an EPSS <1%, indicating a low current exploitation probability but a high potential impact. It is not listed in CISA’s KEV catalog. likely attack vector requires initial network access or a locally compromised host to exploit the default accounts; after gaining access, the attacker could leverage additional weaknesses to raise privileges. The combination of limited account permissions and the threat is significant if the default passwords remain unchanged.
OpenCVE Enrichment