GPU VulnDB

Database/Control plane, storage & DevOps

Cisco UCS Central Software (weak backup encryption): Weak encryption on full-state and configuration backups means

CVE-2024-20280Control plane, storage & DevOpscurated

Impact

Weak encryption on full-state and configuration backups means anyone who obtains a backup file recovers the sensitive information inside it - including the credentials UCS Central uses across the estate.

Who can reach it

Access to a UCS Central backup file. Backups routinely sit on shared file servers and in ticket attachments, which is what makes this practical.

What to do

Upgrade UCS Central per cisco-sa-ucsc-bkpsky-TgJ5f73J, then re-take backups and securely destroy old ones. Rotate credentials contained in previously-generated backups - the patch does not protect files already created.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.