6.5
CVE-2023-20016
- EPSS 0.06%
- Veröffentlicht 23.02.2023 20:15:13
- Zuletzt bearbeitet 21.11.2024 07:40:20
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configuration export feature of Cisco FXOS Software could allow an unauthenticated attacker with access to a backup file to decrypt sensitive information stored in the full state and configuration backup files. This vulnerability is due to a weakness in the encryption method used for the backup function. An attacker could exploit this vulnerability by leveraging a static key used for the backup configuration feature. A successful exploit could allow the attacker to decrypt sensitive information that is stored in full state and configuration backup files, such as local user credentials, authentication server passwords, Simple Network Management Protocol (SNMP) community names, and other credentials.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Ucs Central Software Version < 4.2\(3c\)
Cisco ≫ Ucs 6536 Firmware Version-
Cisco ≫ Ucs Central Software Version < 4.2\(3c\)
Cisco ≫ Ucs 64108 Firmware Version-
Cisco ≫ Ucs Central Software Version < 4.2\(3c\)
Cisco ≫ Ucs 6454 Firmware Version-
Cisco ≫ Ucs Central Software Version < 4.2\(3c\)
Cisco ≫ Ucs 6200 Firmware Version-
Cisco ≫ Ucs Central Software Version < 4.2\(3c\)
Cisco ≫ Ucs 6248up Firmware Version-
Cisco ≫ Ucs Central Software Version < 4.2\(3c\)
Cisco ≫ Ucs 6296up Firmware Version-
Cisco ≫ Ucs Central Software Version < 4.2\(3c\)
Cisco ≫ Ucs 6300 Firmware Version-
Cisco ≫ Ucs Central Software Version < 4.2\(3c\)
Cisco ≫ Ucs 6324 Firmware Version-
Cisco ≫ Ucs Central Software Version < 4.2\(3c\)
Cisco ≫ Ucs 6332 Firmware Version-
Cisco ≫ Ucs Central Software Version < 4.2\(3c\)
Cisco ≫ Ucs 6332-16up Firmware Version-
Cisco ≫ Fxos Version < 2.6.1
Cisco ≫ Firepower 4100 Version-
Cisco ≫ Firepower 4110 Version-
Cisco ≫ Firepower 4112 Version-
Cisco ≫ Firepower 4115 Version-
Cisco ≫ Firepower 4120 Version-
Cisco ≫ Firepower 4125 Version-
Cisco ≫ Firepower 4140 Version-
Cisco ≫ Firepower 4145 Version-
Cisco ≫ Firepower 4150 Version-
Cisco ≫ Firepower 9300 Sm-24 Version-
Cisco ≫ Firepower 9300 Sm-36 Version-
Cisco ≫ Firepower 9300 Sm-40 Version-
Cisco ≫ Firepower 9300 Sm-44 Version-
Cisco ≫ Firepower 9300 Sm-44 X 3 Version-
Cisco ≫ Firepower 9300 Sm-48 Version-
Cisco ≫ Firepower 9300 Sm-56 Version-
Cisco ≫ Firepower 9300 Sm-56 X 3 Version-
Cisco ≫ Firepower 4110 Version-
Cisco ≫ Firepower 4112 Version-
Cisco ≫ Firepower 4115 Version-
Cisco ≫ Firepower 4120 Version-
Cisco ≫ Firepower 4125 Version-
Cisco ≫ Firepower 4140 Version-
Cisco ≫ Firepower 4145 Version-
Cisco ≫ Firepower 4150 Version-
Cisco ≫ Firepower 9300 Sm-24 Version-
Cisco ≫ Firepower 9300 Sm-36 Version-
Cisco ≫ Firepower 9300 Sm-40 Version-
Cisco ≫ Firepower 9300 Sm-44 Version-
Cisco ≫ Firepower 9300 Sm-44 X 3 Version-
Cisco ≫ Firepower 9300 Sm-48 Version-
Cisco ≫ Firepower 9300 Sm-56 Version-
Cisco ≫ Firepower 9300 Sm-56 X 3 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.06% | 0.139 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2 | 4 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
|
psirt@cisco.com | 6.3 | 1.8 | 4 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
|
CWE-321 Use of Hard-coded Cryptographic Key
The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.
CWE-330 Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.