CVE-2010-4302
/opt/rv/Versions/CurrentVersion/Mcu/Config/Mcu.val in Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, uses a weak hashing algorithm for the (1) administrator and (2) operator passwords, which makes it…
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
/opt/rv/Versions/CurrentVersion/Mcu/Config/Mcu.val in Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, uses a weak hashing algorithm for the (1) administrator and (2) operator passwords, which makes it easier for local users to obtain sensitive information by recovering the cleartext values, aka Bug ID CSCti54010.
- CVSS 2.0
- 4.9 MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
- EPSS
- 0.35% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- cisco/unified videoconferencing system 5110 firmware · cisco/unified videoconferencing system 5115 firmware · cisco/unified videoconferencing system 5110 · cisco/unified videoconferencing system 5115
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2010/Nov/167
- http://www.cisco.com/en/US/products/products_security_response09186a0080b56d0d.htmlVendor Advisory
- http://www.trustmatta.com/advisories/MATTA-2010-001.txt
- http://seclists.org/fulldisclosure/2010/Nov/167
- http://www.cisco.com/en/US/products/products_security_response09186a0080b56d0d.htmlVendor Advisory
- http://www.trustmatta.com/advisories/MATTA-2010-001.txt
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.