Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2024-20280 Details

Description

A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files. This vulnerability is due to a weakness in the encryption method that is used for the backup function. An attacker could exploit this vulnerability by accessing a backup file and leveraging a static key that is used for the backup configuration feature. A successful exploit could allow an attacker with access to a backup file to learn sensitive information that is stored in full state backup files and configuration backup files, such as local user credentials, authentication server passwords, Simple Network Management Protocol (SNMP) community names, and the device SSL server certificate and key.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-321Use of Hard-coded Cryptographic Key[email protected]
CWE-798Use of Hard-coded CredentialsCISA-ADP

Affected Products

ProductVersions
cisco ucs central software
1.0(1a)
1.1(1a)
1.1(1b)
1.1(2a)
1.2(1a)

CPE

  • cpe:2.3:a:cisco:ucs_central_software:1.0(1a):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:1.1(1a):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:1.1(1b):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:1.1(2a):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:1.2(1a):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:1.2(1d):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:1.2(1e):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:1.2(1f):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:1.3(1a):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:1.3(1b):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:1.3(1c):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:1.4(1a):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:1.4(1b):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:1.4(1c):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:1.5(1a):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:1.5(1b):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:1.5(1c):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:2.0(1a):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:2.0(1b):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:2.0(1c):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:2.0(1d):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:2.0(1e):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:2.0(1f):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:2.0(1g):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:2.0(1h):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:2.0(1i):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:2.0(1j):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:2.0(1k):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:2.0(1l):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:2.0(1m):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:2.0(1n):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:2.0(1o):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:2.0(1p):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:2.0(1q):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:2.0(1r):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:2.0(1s):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:2.0(1t):*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ucs_central_software:2.0(1u):*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

5 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2024-20280
NVD Published Date:
Oct 16, 2024
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2024-20280 Details - Not Deferred