Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-1219

Опубликовано: 20 янв. 2021
Источник: nvd
CVSS3: 7.8
CVSS3: 7.8
CVSS2: 4.6
EPSS Низкий

Описание

A vulnerability in Cisco Smart Software Manager Satellite could allow an authenticated, local attacker to access sensitive information on an affected system. The vulnerability is due to insufficient protection of static credentials in the affected software. An attacker could exploit this vulnerability by gaining access to the static credential that is stored on the local device. A successful exploit could allow the attacker to view static credentials, which the attacker could use to carry out further attacks.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:smart_software_manager_on-prem:*:*:*:*:*:*:*:*
Версия до 5.1.0 (включая)

EPSS

Процентиль: 14%
0.00047
Низкий

7.8 High

CVSS3

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-798

Связанные уязвимости

github
больше 3 лет назад

A vulnerability in Cisco Smart Software Manager Satellite could allow an authenticated, local attacker to access sensitive information on an affected system. The vulnerability is due to insufficient protection of static credentials in the affected software. An attacker could exploit this vulnerability by gaining access to the static credential that is stored on the local device. A successful exploit could allow the attacker to view static credentials, which the attacker could use to carry out further attacks.

CVSS3: 7.8
fstec
около 5 лет назад

Уязвимость программного средства администрирования лицензий Cisco Smart Software Manager On-Prem, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 14%
0.00047
Низкий

7.8 High

CVSS3

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-798