PT-2024-7336 · Cisco · Cisco Ucs Central
Published
2024-10-16
·
Updated
2024-10-31
·
CVE-2024-20280
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Cisco UCS Central Software (affected versions not specified)
Description:
A weakness in the encryption method used for the backup function in Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information. This information includes local user credentials, authentication server passwords, Simple Network Management Protocol (SNMP) community names, and the device SSL server certificate and key. The vulnerability is due to the use of a static key for the backup configuration feature, which an attacker could exploit by accessing a backup file.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ucs Central