nuclei-templates/file/audit/cisco/set-and-secure-passwords.yaml

33 lines
1.2 KiB
YAML
Raw Normal View History

2022-05-28 08:26:29 +00:00
id: set-and-secure-passwords
info:
name: Cisco Set and Secure Password - Detect
2022-05-28 08:26:29 +00:00
author: pussycat0x
severity: info
2022-05-31 06:23:21 +00:00
description: |
2023-10-14 11:27:55 +00:00
Cisco set and secure password functionality is recommended to control privilege level access. To set a local password to control access to various privilege levels, use the enable password command in global configuration mode. To remove the password requirement, use the no form of this command.
2022-05-31 06:23:21 +00:00
reference:
- https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/d1/sec-d1-cr-book/sec-cr-e1.html#wp3884449514
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
2023-10-14 11:27:55 +00:00
cvss-score: 0
cwe-id: CWE-200
2023-02-24 15:27:00 +00:00
tags: cisco,config-audit,cisco-switch,file
2022-05-28 08:26:29 +00:00
file:
- extensions:
- conf
matchers-condition: and
matchers:
- type: word
words:
- "service password-encryption"
negative: true
- type: word
words:
2023-02-24 15:27:00 +00:00
- "configure terminal"
# Enhanced by md on 2023/05/03
# digest: 490a0046304402207029e29a2d75aea030e8818991a5da7ab7c47204f24a1c238ddcfd78138d8c2e022013f3a96886a9daa37c9df80d46fe6ec3f59a1cce3423fae634016908b8e5ee2c:922c64590222798bb761d5b6d8e72950