Cleartext Password Exposure in Cisco CS-MARS Products
CVE-2009-2977

Currently unrated

Key Information:

Vendor
Cisco
Status
Vendor
CVE Published:
27 August 2009

Summary

The Cisco Security Monitoring, Analysis and Response System (CS-MARS) version 6.0.4 and earlier versions expose sensitive cleartext passwords by storing them in the log/sysbacktrace files located within error-logs.tar.gz archives. This vulnerability allows context-dependent attackers to access these log files, potentially compromising sensitive information. Organizations using the affected versions should take immediate steps to secure their log files and review access controls to mitigate risks associated with this exposure.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.