CVE-2009-0620

CRITICAL

Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.1) uses default (1) usernames and (2) passwords for (a) the administrator and (b) web management,...

Affects 2 products across 1 vendor.

BCS7.28
CVSS 2.010.0
EPSS1.8%
Percentile77th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-255: CWE-255
◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2009. A critical vulnerability affects Cisco systems (CVE-2009-0620). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2009-GLOBAL-082824-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2009-0620?
This vulnerability was disclosed in 2009. A critical vulnerability affects Cisco systems (CVE-2009-0620). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2009-0620?
CVE-2009-0620 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 1.8%.
Is CVE-2009-0620 actively exploited?
No confirmed active exploitation of CVE-2009-0620 as of 2026-05-30.
How do I remediate CVE-2009-0620?
Priority: MEDIUM. Advisory: http://www.cisco.com/en/US/products/products_security_advisory09186a0080a7bc82.shtml PSIRT: [email protected]
What systems are affected by CVE-2009-0620?
CVE-2009-0620 affects: Cisco, Cisco.
Vulnerability Details
CVE IDCVE-2009-0620
BSIDBS-2009-GLOBAL-082824-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2009-02-26
Last Modified2026-04-23
ICS Relevance75%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.1) uses default (1) usernames and (2) passwords for (a) the administrator and (b) web management, which makes it easier for remote attackers to perform configuration changes or obtain operating-system access.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.1) uses default (1) usernames and (2) passwords for (a) the administrator and (b) web management, which makes it easier for remote attackers to perform configuration changes or obtain operating-system access. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Cisco Catalyst
Cisco Application Control Engine Module
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 6369 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashb63698b4ea28ed91a6807e6bfc8eaa7a1ecdcc109583a0a07dad0be066bb8f266dcfec56e29d303c53cf103597e2f66ca3d19d102e6f9fd88b0e379b35d4b014
Related CVEs affecting Cisco
CVE-2008-0529 10.0 Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, ... CVE-2007-2036 10.0 The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 200... CVE-2011-2555 10.0 Cisco TelePresence Recording Server 1.7.2.x before 1.7.2.1 has a default pass... CVE-1999-0775 10.0 Cisco Gigabit Switch routers running IOS allow remote attackers to forward un... CVE-2002-1358 10.0 Multiple SSH2 servers and clients do not properly handle lists with empty ele...
View all Cisco CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →