5
CVSSv2

CVE-2014-0694

Published: 14/03/2014 Updated: 14/03/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Intelligent Automation for Cloud (IAC) in Cisco Cloud Portal 9.4.1 and previous versions includes a cryptographic key in binary files, which makes it easier for remote malicious users to obtain cleartext data from an arbitrary IAC installation by leveraging knowledge of this key, aka Bug IDs CSCui34764, CSCui34772, CSCui34776, CSCui34798, CSCui34800, CSCui34805, CSCui34809, CSCui34810, CSCui34813, CSCui34814, and CSCui34818.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco cloud portal 9.3.1

cisco cloud portal 9.3.2

cisco cloud portal 9.4

cisco cloud portal 9.1

cisco cloud portal 9.3

cisco cloud portal

Vendor Advisories

Issues in the cryptographic implementation of Cisco Intelligent Automation for Cloud (Cisco IAC) may allow an unauthenticated, remote attacker to recover cryptographic material used in all Cisco IAC installations The issues are due to the inclusion of fixed cryptographic material in the product binaries An attacker that could gain access to encr ...