PT-2024-7336 · Cisco · Cisco Ucs Central

Published

2024-10-16

·

Updated

2024-10-31

·

CVE-2024-20280

CVSS v3.1

6.3

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Cisco UCS Central Software (affected versions not specified)
Description: A weakness in the encryption method used for the backup function in Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information. This information includes local user credentials, authentication server passwords, Simple Network Management Protocol (SNMP) community names, and the device SSL server certificate and key. The vulnerability is due to the use of a static key for the backup configuration feature, which an attacker could exploit by accessing a backup file.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2024-08692
CVE-2024-20280

Affected Products

Cisco Ucs Central