Cisco has issued a security advisory for Cisco Network Assurance Engine (NAE) Release 3.0(1) for a bug that causes password changes done via NAE to not be synchronized to the device’s command console. This would allow a user to be able to gain access to a device via its CLI using the previous password. The vulnerability has been fixed in Cisco NAE Release 3(1a) Once this update is installed, you should change the administrator password again from the management web interface to properly synchronize the passwords.
Source: https://www.bleepingcomputer.com/news/security/cisco-network-assurance-engine-bug-allows-login-with-old-passwords/

