CVE-2018-15407
published 2018-10-05CVE-2018-15407: A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information. The…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.29%
20.6th percentile
A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information. The vulnerability is due to insufficient cleanup of installation files. An attacker could exploit this vulnerability by accessing the residual installation files on an affected system. A successful exploit could allow the attacker to collect sensitive information regarding the configuration of the system.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_hyperflex_hx-series | — | — |
| cisco | hyperflex_hx_data_platform | — | — |
| cisco | hyperflex_world-readable_sensitive | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco HyperFlex World-Readable Sensitive Information Vulnerability
vendor_cisco·2018-10-03·CVSS 5.5
CVE-2018-15407 [MEDIUM] CWE-459 Cisco HyperFlex World-Readable Sensitive Information Vulnerability
Cisco HyperFlex World-Readable Sensitive Information Vulnerability
A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information.
The vulnerability is due to insufficient cleanup of installation files. An attacker could exploit this vulnerability by accessing the residual installation files on an affected system. A successful exploit could allow the attacker to collect sensitive information regarding the configuration of the system.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181003-hyperflex-info
Cisco
Cisco HyperFlex World-Readable Sensitive Information Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-15407 Cisco HyperFlex World-Readable Sensitive Information Vulnerability
CVE-2018-15407: Cisco HyperFlex World-Readable Sensitive Information Vulnerability
A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information. The vulnerability is due to insufficient cleanup of installation files. An attacker could exploit this vulnerability by accessing the residual installation files on an affected system. A successful exploit could allow the attacker to collect sensitive information regarding the configuration of the system. There are no
CVSS: 3.0
CWE: CWE-459, CWE-459
Bug IDs: CSCvk59406
GHSA
GHSA-qg7x-r68h-9889: A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information
ghsa_unreviewed·2022-05-13
CVE-2018-15407 [MEDIUM] CWE-459 GHSA-qg7x-r68h-9889: A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information
A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information. The vulnerability is due to insufficient cleanup of installation files. An attacker could exploit this vulnerability by accessing the residual installation files on an affected system. A successful exploit could allow the attacker to collect sensitive information regarding the configuration of the system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-10-05
Published