A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information. The vulnerability is due to insufficient cleanup of installation files. An attacker could exploit this vulnerability by accessing the residual installation files on an affected system. A successful exploit could allow the attacker to collect sensitive information regarding the configuration of the system.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-7285 A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information. The vulnerability is due to insufficient cleanup of installation files. An attacker could exploit this vulnerability by accessing the residual installation files on an affected system. A successful exploit could allow the attacker to collect sensitive information regarding the configuration of the system.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 26 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-26T14:31:37.493Z

Reserved: 2018-08-17T00:00:00

Link: CVE-2018-15407

cve-icon Vulnrichment

Updated: 2024-08-05T09:54:02.560Z

cve-icon NVD

Status : Modified

Published: 2018-10-05T14:29:09.137

Modified: 2024-11-21T03:50:43.440

Link: CVE-2018-15407

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.