CVE-2024-20280 — Use of Hard-coded Cryptographic Key in Cisco Unified Computing System Central Software
Severity
6.3MEDIUMNVD
EPSS
0.1%
top 74.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Description
A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files.
This vulnerability is due to a weakness in the encryption method that is used for the backup function. An attacker could exploit this vulnerability by accessing a backup file and leveraging a static key that is used for the backup configuration feature. A successful exploit could a…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:NExploitability: 1.8 | Impact: 4.0
Affected Packages2 packages
🔴Vulnerability Details
2📋Vendor Advisories
1Cisco
▶