CVE-2020-3389Missing Encryption of Sensitive Data in Cisco Hyperflex HX Data Platform

Severity
4.4MEDIUMNVD
EPSS
0.0%
top 89.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 26
Latest updateMay 24

Description

A vulnerability in the installation component of Cisco Hyperflex HX-Series Software could allow an authenticated, local attacker to retrieve the password that was configured at installation on an affected device. The vulnerability exists because sensitive information is stored as clear text. An attacker could exploit this vulnerability by authenticating to an affected device and navigating to the directory that contains sensitive information. A successful exploit could allow the attacker to obta

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 0.8 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-4hvh-wv6j-q2j4: A vulnerability in the installation component of Cisco Hyperflex HX-Series Software could allow an authenticated, local attacker to retrieve the passw2022-05-24
CVEList
Cisco Hyperflex HX-Series Software Weak Storage Vulnerability2020-08-26

📋Vendor Advisories

1
Cisco
Cisco Hyperflex HX-Series Software Weak Storage Vulnerability2020-08-19
CVE-2020-3389 — Missing Encryption of Sensitive Data | cvebase