CVE-2021-1219

A vulnerability in Cisco Smart Software Manager Satellite could allow an authenticated, local attacker to access sensitive information on an affected system. The vulnerability is due to insufficient protection of static credentials in the affected software. An attacker could exploit this vulnerability by gaining access to the static credential that is stored on the local device. A successful exploit could allow the attacker to view static credentials, which the attacker could use to carry out further attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cisco:smart_software_manager_on-prem:*:*:*:*:*:*:*:*

History

28 Jan 2021, 18:00

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.6
v3 : 7.8
References (CISCO) https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-sc-Jd42D4Tq - (CISCO) https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-sc-Jd42D4Tq - Vendor Advisory
CPE cpe:2.3:a:cisco:smart_software_manager_on-prem:*:*:*:*:*:*:*:*

26 Jan 2021, 18:16

Type Values Removed Values Added
Summary A vulnerability in Cisco Smart Software Manager Satellite could allow an authenticated, local attacker to access sensitive information on an affected system. The vulnerability is due to insufficient protection of static credentials in the affected software. An attacker could exploit this vulnerability by gaining access to the static credential that is stored on the local device. A successful exploit could allow the attacker to view static credentials, which the attacker could use to carry out further attacks. A vulnerability in Cisco Smart Software Manager Satellite could allow an authenticated, local attacker to access sensitive information on an affected system. The vulnerability is due to insufficient protection of static credentials in the affected software. An attacker could exploit this vulnerability by gaining access to the static credential that is stored on the local device. A successful exploit could allow the attacker to view static credentials, which the attacker could use to carry out further attacks.

20 Jan 2021, 21:31

Type Values Removed Values Added
New CVE

Information

Published : 2021-01-20 21:15

Updated : 2023-12-10 13:41


NVD link : CVE-2021-1219

Mitre link : CVE-2021-1219

CVE.ORG link : CVE-2021-1219


JSON object : View

Products Affected

cisco

  • smart_software_manager_on-prem
CWE
CWE-798

Use of Hard-coded Credentials