Riverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism by leveraging knowledge of the password algorithm and the appliance serial number
Published Apr 4, 2017
6.4
MEDIUMCVSS 3.1
EPSS 0.36%
Description
Riverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism by leveraging knowledge of the password algorithm and the appliance serial number. NOTE: the vendor believes that this does not meet the definition of a vulnerability. The product contains correct computational logic for supporting arbitrary password changes by customers; however, a password change is optional to meet different customers' needs
Affected products
No data.
-
- Version 0StatusaffectedConstraints<=9.6.0
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:L/AC:M/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jul 23, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.36% (0.00361) | 27.51th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.36% (0.00361) | 29.89th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.09% (0.00088) | 38.30th | v3 (v2023.03.01) |
| Jun 26, 2024 | 0.09% (0.00088) | 38.14th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.09% (0.00088) | 36.12th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00885) | 10.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.62% (0.00624) | 17.80th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.62% (0.00624) | 0.00th | v1 |
References (2)
- http://seclists.org/fulldisclosure/2017/Feb/25 x_refsource_MISCExploitTechnical DescriptionThird Party Advisory
- https://supportkb.riverbed.com/support/index?page=content&id=S30065 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://seclists.org/fulldisclosure/2017/Feb/25 | x_refsource_MISCExploitTechnical DescriptionThird Party Advisory | |
| https://supportkb.riverbed.com/support/index?page=content&id=S30065 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.