PT-2021-5130 · Cisco · Thousandeyes Recorder

Published

2021-06-02

·

Updated

2021-06-14

·

CVE-2021-1537

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco ThousandEyes Recorder (affected versions not specified)
Description The issue is related to insufficient protection of registration data in the installer software. An unauthenticated, local attacker could exploit this to access sensitive information contained in the ThousandEyes Recorder installer software. This is possible because sensitive information is included in the application installer. An attacker could exploit this by downloading the installer and extracting its contents, potentially allowing access to sensitive information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05924
CVE-2021-1537

Affected Products

Thousandeyes Recorder