CVE-2024-20280
published 2024-10-16CVE-2024-20280: A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is…
PriorityP429medium6.3CVSS 3.1
AVLACLPRNUIRSCCHINAN
EPSS
0.11%
1.6th percentile
A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files.
This vulnerability is due to a weakness in the encryption method that is used for the backup function. An attacker could exploit this vulnerability by accessing a backup file and leveraging a static key that is used for the backup configuration feature. A successful exploit could allow an attacker with access to a backup file to learn sensitive information that is stored in full state backup files and configuration backup files, such as local user credentials, authentication server passwords, Simple Network Management Protocol (SNMP) community names, and the device SSL server certificate and key.
Affected
77 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
| cisco | cisco_unified_computing_system_central_software | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
vendor_cisco6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco UCS Central Software Configuration Backup Information Disclosure Vulnerability
vendor_cisco·2024-10-16·CVSS 6.3
CVE-2024-20280 [MEDIUM] CWE-321 Cisco UCS Central Software Configuration Backup Information Disclosure Vulnerability
Cisco UCS Central Software Configuration Backup Information Disclosure Vulnerability
A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files.
This vulnerability is due to a weakness in the encryption method that is used for the backup function. An attacker could exploit this vulnerability by accessing a backup file and leveraging a static key that is used for the backup configuration feature. A successful exploit could allow an attacker with access to a backup file to learn sensitive information that is stored in full state backup files and configuration backup files, such as local user credentials, authentication server passwords
Cisco
Cisco UCS Central Software Configuration Backup Information Disclosure Vulnerability
vendor_cisco·CVSS 3.1
CVE-2024-20280 Cisco UCS Central Software Configuration Backup Information Disclosure Vulnerability
CVE-2024-20280: Cisco UCS Central Software Configuration Backup Information Disclosure Vulnerability
A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files. This vulnerability is due to a weakness in the encryption method that is used for the backup function. An attacker could exploit this vulnerability by accessing a backup file and leveraging a static key that is used for the backup configuration feature. A successful exploit could allow an attacker with access to a backup file to learn sensitive information that is stored in full state backup files and configuration backup files, such as local user credentials, authentication se
GHSA
GHSA-jm5c-w4xp-6794: A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive informatio
ghsa_unreviewed·2024-10-16
CVE-2024-20280 [MEDIUM] CWE-321 GHSA-jm5c-w4xp-6794: A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive informatio
A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files.
This vulnerability is due to a weakness in the encryption method that is used for the backup function. An attacker could exploit this vulnerability by accessing a backup file and leveraging a static key that is used for the backup configuration feature. A successful exploit could allow an attacker with access to a backup file to learn sensitive information that is stored in full state backup files and configuration backup files, such as local user credentials, authentication server passwords, Simple Network Management Protocol (SNMP) community names, and the device SSL server
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-16
Published