cbcvebase.
CVE-2024-20280
published 2024-10-16

CVE-2024-20280: A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is…

PriorityP429medium6.3CVSS 3.1
AVLACLPRNUIRSCCHINAN
EPSS
0.11%
1.6th percentile
A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files. This vulnerability is due to a weakness in the encryption method that is used for the backup function. An attacker could exploit this vulnerability by accessing a backup file and leveraging a static key that is used for the backup configuration feature. A successful exploit could allow an attacker with access to a backup file to learn sensitive information that is stored in full state backup files and configuration backup files, such as local user credentials, authentication server passwords, Simple Network Management Protocol (SNMP) community names, and the device SSL server certificate and key.

Affected

77 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software
ciscocisco_unified_computing_system_central_software

CVSS provenance

nvdv3.16.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
vendor_cisco6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.