Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-27125

Опубликовано: 17 нояб. 2020
Источник: nvd
CVSS3: 7.4
CVSS3: 9.8
CVSS2: 5
EPSS Низкий

Описание

A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability is due to insufficient protection of static credentials in the affected software. An attacker could exploit this vulnerability by viewing source code. A successful exploit could allow the attacker to view static credentials, which the attacker could use to carry out further attacks.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:security_manager:*:*:*:*:*:*:*:*
Версия до 4.21 (включая)

EPSS

Процентиль: 78%
0.01109
Низкий

7.4 High

CVSS3

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
CWE-20

Связанные уязвимости

github
больше 3 лет назад

A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability is due to insufficient protection of static credentials in the affected software. An attacker could exploit this vulnerability by viewing source code. A successful exploit could allow the attacker to view static credentials, which the attacker could use to carry out further attacks.

CVSS3: 7.4
fstec
около 5 лет назад

Уязвимость статических ученых данных программного средства для создания отчетов для развернутых средств безопасности Cisco Security Manager, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 78%
0.01109
Низкий

7.4 High

CVSS3

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
CWE-20