Cisco RCM for StarOS Software Vulnerability Could Lead to Information Disclosure
CVE-2022-20648

5.3MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
15 November 2024

Summary

A vulnerability exists in the debug functionality of Cisco RCM for Cisco StarOS Software that may permit unauthenticated, remote attackers to execute debug commands. This could lead to unauthorized access to sensitive information intended to be kept confidential. The vulnerability arises from a debug service that improperly listens for and accepts connections, thereby allowing exploitation through the debug port. Cisco has issued updates for their software to mitigate this issue, and no effective workarounds are available.

Affected Version(s)

Cisco Redundancy Configuration Manager 2021.02.0

Cisco Redundancy Configuration Manager 2021.01.0

Cisco Redundancy Configuration Manager 21.19.n13

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.