SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-4302

/opt/rv/Versions/CurrentVersion/Mcu/Config/Mcu.val in Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, uses a weak hashing algorithm for the (1) administrator and (2) operator passwords, which makes it…

MEDIUM 4.9EPSS 0.35%

Does this matter?

Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.

Description

/opt/rv/Versions/CurrentVersion/Mcu/Config/Mcu.val in Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, uses a weak hashing algorithm for the (1) administrator and (2) operator passwords, which makes it easier for local users to obtain sensitive information by recovering the cleartext values, aka Bug ID CSCti54010.

CVSS 2.0
4.9 MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
EPSS
0.35% probability · 29th percentile
CISA KEV
Not listed
Weakness
CWE-310
Affected
cisco/unified videoconferencing system 5110 firmware · cisco/unified videoconferencing system 5115 firmware · cisco/unified videoconferencing system 5110 · cisco/unified videoconferencing system 5115
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.