A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files. This vulnerability is due to a weakness in the encryption method that is used for the backup function. An attacker could exploit this vulnerability by accessing a backup file and leveraging a static key that is used for the backup configuration feature. A successful exploit could allow an attacker with access to a backup file to learn sensitive information that is stored in full state backup files and configuration backup files, such as local user credentials, authentication server passwords, Simple Network Management Protocol (SNMP) community names, and the device SSL server certificate and key.
History

Thu, 31 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-798

Wed, 16 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Oct 2024 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files. This vulnerability is due to a weakness in the encryption method that is used for the backup function. An attacker could exploit this vulnerability by accessing a backup file and leveraging a static key that is used for the backup configuration feature. A successful exploit could allow an attacker with access to a backup file to learn sensitive information that is stored in full state backup files and configuration backup files, such as local user credentials, authentication server passwords, Simple Network Management Protocol (SNMP) community names, and the device SSL server certificate and key.
Title Cisco UCS Central Software Configuration Backup Static Key Vulnerability
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2024-10-16T16:15:37.008Z

Updated: 2024-10-31T14:13:19.791Z

Reserved: 2023-11-08T15:08:07.626Z

Link: CVE-2024-20280

cve-icon Vulnrichment

Updated: 2024-10-16T18:30:50.106Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-16T17:15:13.697

Modified: 2024-10-31T15:35:23.060

Link: CVE-2024-20280

cve-icon Redhat

No data.