CVE-2024-20280Use of Hard-coded Cryptographic Key in Cisco Unified Computing System Central Software

Severity
6.3MEDIUMNVD
EPSS
0.1%
top 74.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16

Description

A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files. This vulnerability is due to a weakness in the encryption method that is used for the backup function. An attacker could exploit this vulnerability by accessing a backup file and leveraging a static key that is used for the backup configuration feature. A successful exploit could a

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:NExploitability: 1.8 | Impact: 4.0

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
Cisco UCS Central Software Configuration Backup Static Key Vulnerability2024-10-16
GHSA
GHSA-jm5c-w4xp-6794: A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive informatio2024-10-16

📋Vendor Advisories

1
Cisco
Cisco UCS Central Software Configuration Backup Information Disclosure Vulnerability2024-10-16
CVE-2024-20280 — Use of Hard-coded Cryptographic Key | cvebase