Cleartext Password Exposure in Cisco CS-MARS Products
CVE-2009-2977
Currently unrated
Summary
The Cisco Security Monitoring, Analysis and Response System (CS-MARS) version 6.0.4 and earlier versions expose sensitive cleartext passwords by storing them in the log/sysbacktrace files located within error-logs.tar.gz archives. This vulnerability allows context-dependent attackers to access these log files, potentially compromising sensitive information. Organizations using the affected versions should take immediate steps to secure their log files and review access controls to mitigate risks associated with this exposure.
References
Timeline
Vulnerability published
Vulnerability Reserved