CVE-2015-4213
published 2015-06-24CVE-2015-4213: Cisco NX-OS 1.1(1g) on Nexus 9000 devices allows remote authenticated users to discover cleartext passwords by leveraging the existence of a decryption…
PriorityP422medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
2.63%
83.9th percentile
Cisco NX-OS 1.1(1g) on Nexus 9000 devices allows remote authenticated users to discover cleartext passwords by leveraging the existence of a decryption mechanism, aka Bug ID CSCuu84391.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nx-os | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xj7r-q24h-7jww: Cisco NX-OS 1
ghsa_unreviewed·2022-05-17
CVE-2015-4213 [MEDIUM] CWE-200 GHSA-xj7r-q24h-7jww: Cisco NX-OS 1
Cisco NX-OS 1.1(1g) on Nexus 9000 devices allows remote authenticated users to discover cleartext passwords by leveraging the existence of a decryption mechanism, aka Bug ID CSCuu84391.
Cisco
Cisco Nexus 9000 Series Software Password Exposure Vulnerability
vendor_cisco·2015-06-23·CVSS 4.0
CVE-2015-4213 [MEDIUM] CWE-200 Cisco Nexus 9000 Series Software Password Exposure Vulnerability
Cisco Nexus 9000 Series Software Password Exposure Vulnerability
A vulnerability in Cisco Nexus 9000 Series Software could allow an authenticated, remote attacker to expose passwords in plain text format.
The vulnerability is due to older versions of the affected software retaining the ability to decrypt passwords. An attacker could exploit this vulnerability to expose passwords in plain text format.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement reduces the likelihood of a successful exploit.
Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-24
Published