Cisco Prime Central for HCS Portal Credentials Access Vulnerability

Related Vulnerabilities: CVE-2013-3409  

A vulnerability in Cisco Prime Central for HCS portal could allow an authenticated, local attacker to retrieve the credentials for accounts. The vulnerability is due to plaintext logging of credentials to temporary files with inadequate permissions. An attacker could exploit this vulnerability by accessing the files to acquire credentials and using them to access internal application components, such as the database. Cisco has confirmed the vulnerability in a security notice; however, software updates are not available. An attacker would need to authenticate and have local access to the targeted device. This access requirement decreases the likelihood of a successful attack.