5
CVSSv2

CVE-2014-8009

Published: 10/12/2014 Updated: 24/01/2015
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Management subsystem in Cisco Unified Computing System 2.1(3f) and previous versions allows remote malicious users to obtain sensitive information by reading log files, aka Bug ID CSCur99239.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified computing system

Vendor Advisories

A vulnerability in the system logs of the Cisco Unified Computing System Manager could allow an unauthenticated, remote attacker to view sensitive system information The vulnerability is due to the inclusion of sensitive information in certain log files An attacker could exploit this vulnerability by viewing the sensitive information stored in t ...

Exploits

Cisco Unified Computing System Manager (UCSM) versions 13 through 22 sends local (UCSM) username and password hashes to the configured SYSLOG server every 12 hours ...