Database/Control plane, storage & DevOps
Cisco UCS Central Software (weak backup encryption): Weak encryption on full-state and configuration backups means
Impact
Weak encryption on full-state and configuration backups means anyone who obtains a backup file recovers the sensitive information inside it - including the credentials UCS Central uses across the estate.
Who can reach it
Access to a UCS Central backup file. Backups routinely sit on shared file servers and in ticket attachments, which is what makes this practical.
What to do
Upgrade UCS Central per cisco-sa-ucsc-bkpsky-TgJ5f73J, then re-take backups and securely destroy old ones. Rotate credentials contained in previously-generated backups - the patch does not protect files already created.
References
Related entries
- Dell OpenManage Enterprise (credential disclosure): A low-privileged local user obtains stored credentials from OMECVE-2024-28961 · Dell OpenManage Enterprise (credential disclosure)Medium
- Grafana: org admin can delete other organizations' snapshots and recover delete keys from share keysCVE-2026-19197 · Grafana (dashboard snapshot API)Medium
- CZ.NIC BIRD Internet Routing Daemon (BGP AS_PATH mask matching): Stack-based buffer overflow in BIRD's AS_PATH maskCVE-2026-49943 · CZ.NIC BIRD Internet Routing Daemon (BGP AS_PATH mask matching)Medium
- Jenkins: agent config update names its own target, letting one agent's configurer take over anotherCVE-2026-84651 · Jenkins controller (REST API and CLI agent configuration update)Medium
- Prometheus (exporter-toolkit): Poisoning the built-in auth cache bypasses basic-auth on exportersCVE-2022-46146 · Prometheus (exporter-toolkit)Medium
- OpenTelemetry eBPF Profiler: unprivileged process can stall the agent by mapping a FIFOCVE-2026-48496 · OpenTelemetry eBPF Profiler (ELF mapping file handling)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.