Impact
This vulnerability arises from insufficiently protected credentials, classified under CWE‑522. It enables an attacker to discover or harvest stored authentication material, thereby gaining unauthorized access to the Cisco Crosswork Planning system. Because credential access could allow further exploitation of the platform, the potential impact includes compromise of sensitive configuration data and the ability to perform privileged actions beyond the intended user scope.
Affected Systems
Cisco Crosswork Planning is the product impacted by the release. No specific version information is provided in the advisory, so the vulnerability may affect all current deployments of this product pending the application of the hardening release.
Risk and Exploitability
The CVSS score of 9.9 indicates a critical severity, and while the EPSS score is not available, the absence of a KEV listing does not diminish the likelihood of exploitation. The attack vector is not specified in the advisory, but given the nature of credential storage vulnerabilities, a remote or local attacker who can access the storage mechanism could exploit it. The high severity and lack of mitigation details in the environment make the risk significant until the hardening release is applied.
OpenCVE Enrichment