← Vulnerability feed

Vulnerability record · CVE-2009-0620 · published 26 February 2009

CVE-2009-0620: Cisco application control engine module vulnerability

Cisco · Application Control Engine Module

Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.1) uses default (1) usernames and (2) passwords for (a) the administrator and (b) web management, which makes it easier for remote attackers to perform configuration changes or obtain operating-system access.

10.0 CVSS 2.0 High EPSS 1.8% · top 21.6% CWE-255 · CWE-255
10.0CVSS 2.0 base score
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.1) uses default (1) usernames and (2) passwords for (a) the administrator and (b) web management, which makes it easier for remote attackers to perform configuration changes or obtain operating-system access.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-0620 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.0CVE-2009-0622Cisco application control engine module vulnerabilityUnspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.2) and Cisco ACE 471…EPSS 1.5%7.8CVE-2009-0742Cisco application control engine module vulnerabilityThe username command in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers and Cisco ACE 4710 Application Contro…EPSS 1.1%7.8CVE-2009-0625Cisco ace 4710 code injection vulnerabilityUnspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.2) and Cisco ACE 471…EPSS 1.7%7.8CVE-2009-0623Cisco ace 4710 vulnerabilityUnspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.3) and Cisco ACE 471…EPSS 1.3%6.8CVE-2009-0624Cisco application control engine module vulnerabilityUnspecified vulnerability in the SNMPv2c implementation in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers be…EPSS 1.3%5.0CVE-2012-3919Cisco application control engine module vulnerabilityThe Cisco Application Control Engine (ACE) module 3.0 for Cisco Catalyst switches and Cisco routers does not properly monitor Load Balancer (LB) queu…EPSS 1.2%8.8CVE-2014-1812Microsoft Windows Group Policy Preferences credential exposure and privilege escalationGroup Policy Preferences in multiple Windows versions stored and distributed passwords in a way that did not properly protect them, allowing any auth…KEVEPSS 65%analysed

Source: NIST National Vulnerability Database (record CVE-2009-0620), CISA KEV, FIRST EPSS (scores of 2026-10-10). This page is refreshed as NVD updates the record.