Executive brief
Ciena's network management and control software contains hidden internal system accounts with predictable default passwords. These tools are used by telecommunications providers to manage and automate large-scale network infrastructure. While these accounts have limited access on their own, an attacker could use them as a starting point to gain higher-level control over the system, potentially disrupting network operations or accessing sensitive configuration data.
Technical details
The vulnerability (CWE-1393) involves the use of default, predictable passwords for hidden system accounts within Ciena's Navigator NCS, MCP, and Planner Plus OnPrem platforms. These accounts are intended for internal software operations and possess restricted permissions. However, an attacker who identifies these credentials can establish a foothold on the system. By chaining this access with other potential vulnerabilities, an attacker could achieve privilege escalation. The vulnerability is present in Navigator NCS version 8.1, MCP versions 8.0 and earlier, and Planner Plus OnPrem versions 4.1 and earlier.
Affected products
- Ciena Navigator Network Control Suite (NCS) 8.1
- Ciena Manage Control Plan (MCP) <= 8.0
- Ciena Planner Plus OnPrem <= 4.1
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory