Cisco RCM for StarOS Software Vulnerability Could Lead to Information Disclosure
CVE-2022-20648
5.3MEDIUM
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 15 November 2024
What is CVE-2022-20648?
A vulnerability exists in the debug functionality of Cisco RCM for Cisco StarOS Software that may permit unauthenticated, remote attackers to execute debug commands. This could lead to unauthorized access to sensitive information intended to be kept confidential. The vulnerability arises from a debug service that improperly listens for and accepts connections, thereby allowing exploitation through the debug port. Cisco has issued updates for their software to mitigate this issue, and no effective workarounds are available.
Affected Version(s)
Cisco Redundancy Configuration Manager 2021.02.0
Cisco Redundancy Configuration Manager 2021.01.0
Cisco Redundancy Configuration Manager 21.19.n13