CVE-2023-20016
Cisco FXOS Software and UCS Manager Software Configuration Backup Static Key Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configuration export feature of Cisco FXOS Software could allow an unauthenticated attacker with access to a backup file to decrypt sensitive information stored in the full state and configuration backup files. This vulnerability is due to a weakness in the encryption method used for the backup function. An attacker could exploit this vulnerability by leveraging a static key used for the backup configuration feature. A successful exploit could allow the attacker to decrypt sensitive information that is stored in full state and configuration backup files, such as local user credentials, authentication server passwords, Simple Network Management Protocol (SNMP) community names, and other credentials.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2022-10-27 CVE Reserved
- 2023-02-23 CVE Published
- 2023-03-08 EPSS Updated
- 2024-10-25 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-321: Use of Hard-coded Cryptographic Key
- CWE-330: Use of Insufficiently Random Values
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Ucs Central Software Search vendor "Cisco" for product "Ucs Central Software" | < 4.2\(3c\) Search vendor "Cisco" for product "Ucs Central Software" and version " < 4.2\(3c\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Ucs 6536 Search vendor "Cisco" for product "Ucs 6536" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ucs 6536 Firmware Search vendor "Cisco" for product "Ucs 6536 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Ucs 6536 Search vendor "Cisco" for product "Ucs 6536" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ucs Central Software Search vendor "Cisco" for product "Ucs Central Software" | < 4.2\(3c\) Search vendor "Cisco" for product "Ucs Central Software" and version " < 4.2\(3c\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Ucs 64108 Search vendor "Cisco" for product "Ucs 64108" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ucs 64108 Firmware Search vendor "Cisco" for product "Ucs 64108 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Ucs 64108 Search vendor "Cisco" for product "Ucs 64108" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ucs Central Software Search vendor "Cisco" for product "Ucs Central Software" | < 4.2\(3c\) Search vendor "Cisco" for product "Ucs Central Software" and version " < 4.2\(3c\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Ucs 6454 Search vendor "Cisco" for product "Ucs 6454" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ucs 6454 Firmware Search vendor "Cisco" for product "Ucs 6454 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Ucs 6454 Search vendor "Cisco" for product "Ucs 6454" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ucs Central Software Search vendor "Cisco" for product "Ucs Central Software" | < 4.2\(3c\) Search vendor "Cisco" for product "Ucs Central Software" and version " < 4.2\(3c\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Ucs 6200 Search vendor "Cisco" for product "Ucs 6200" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ucs 6200 Firmware Search vendor "Cisco" for product "Ucs 6200 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Ucs 6200 Search vendor "Cisco" for product "Ucs 6200" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ucs Central Software Search vendor "Cisco" for product "Ucs Central Software" | < 4.2\(3c\) Search vendor "Cisco" for product "Ucs Central Software" and version " < 4.2\(3c\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Ucs 6248up Search vendor "Cisco" for product "Ucs 6248up" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ucs 6248up Firmware Search vendor "Cisco" for product "Ucs 6248up Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Ucs 6248up Search vendor "Cisco" for product "Ucs 6248up" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ucs Central Software Search vendor "Cisco" for product "Ucs Central Software" | < 4.2\(3c\) Search vendor "Cisco" for product "Ucs Central Software" and version " < 4.2\(3c\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Ucs 6296up Search vendor "Cisco" for product "Ucs 6296up" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ucs 6296up Firmware Search vendor "Cisco" for product "Ucs 6296up Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Ucs 6296up Search vendor "Cisco" for product "Ucs 6296up" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ucs Central Software Search vendor "Cisco" for product "Ucs Central Software" | < 4.2\(3c\) Search vendor "Cisco" for product "Ucs Central Software" and version " < 4.2\(3c\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Ucs 6300 Search vendor "Cisco" for product "Ucs 6300" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ucs 6300 Firmware Search vendor "Cisco" for product "Ucs 6300 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Ucs 6300 Search vendor "Cisco" for product "Ucs 6300" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ucs Central Software Search vendor "Cisco" for product "Ucs Central Software" | < 4.2\(3c\) Search vendor "Cisco" for product "Ucs Central Software" and version " < 4.2\(3c\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Ucs 6324 Search vendor "Cisco" for product "Ucs 6324" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ucs 6324 Firmware Search vendor "Cisco" for product "Ucs 6324 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Ucs 6324 Search vendor "Cisco" for product "Ucs 6324" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ucs Central Software Search vendor "Cisco" for product "Ucs Central Software" | < 4.2\(3c\) Search vendor "Cisco" for product "Ucs Central Software" and version " < 4.2\(3c\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Ucs 6332 Search vendor "Cisco" for product "Ucs 6332" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ucs 6332 Firmware Search vendor "Cisco" for product "Ucs 6332 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Ucs 6332 Search vendor "Cisco" for product "Ucs 6332" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ucs Central Software Search vendor "Cisco" for product "Ucs Central Software" | < 4.2\(3c\) Search vendor "Cisco" for product "Ucs Central Software" and version " < 4.2\(3c\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Ucs 6332-16up Search vendor "Cisco" for product "Ucs 6332-16up" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ucs 6332-16up Firmware Search vendor "Cisco" for product "Ucs 6332-16up Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Ucs 6332-16up Search vendor "Cisco" for product "Ucs 6332-16up" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fxos Search vendor "Cisco" for product "Fxos" | < 2.6.1 Search vendor "Cisco" for product "Fxos" and version " < 2.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 4100 Search vendor "Cisco" for product "Firepower 4100" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fxos Search vendor "Cisco" for product "Fxos" | < 2.6.1 Search vendor "Cisco" for product "Fxos" and version " < 2.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 4110 Search vendor "Cisco" for product "Firepower 4110" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fxos Search vendor "Cisco" for product "Fxos" | < 2.6.1 Search vendor "Cisco" for product "Fxos" and version " < 2.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 4112 Search vendor "Cisco" for product "Firepower 4112" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fxos Search vendor "Cisco" for product "Fxos" | < 2.6.1 Search vendor "Cisco" for product "Fxos" and version " < 2.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 4115 Search vendor "Cisco" for product "Firepower 4115" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fxos Search vendor "Cisco" for product "Fxos" | < 2.6.1 Search vendor "Cisco" for product "Fxos" and version " < 2.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 4120 Search vendor "Cisco" for product "Firepower 4120" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fxos Search vendor "Cisco" for product "Fxos" | < 2.6.1 Search vendor "Cisco" for product "Fxos" and version " < 2.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 4125 Search vendor "Cisco" for product "Firepower 4125" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fxos Search vendor "Cisco" for product "Fxos" | < 2.6.1 Search vendor "Cisco" for product "Fxos" and version " < 2.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 4140 Search vendor "Cisco" for product "Firepower 4140" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fxos Search vendor "Cisco" for product "Fxos" | < 2.6.1 Search vendor "Cisco" for product "Fxos" and version " < 2.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 4145 Search vendor "Cisco" for product "Firepower 4145" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fxos Search vendor "Cisco" for product "Fxos" | < 2.6.1 Search vendor "Cisco" for product "Fxos" and version " < 2.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 4150 Search vendor "Cisco" for product "Firepower 4150" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fxos Search vendor "Cisco" for product "Fxos" | < 2.6.1 Search vendor "Cisco" for product "Fxos" and version " < 2.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 9300 Sm-24 Search vendor "Cisco" for product "Firepower 9300 Sm-24" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fxos Search vendor "Cisco" for product "Fxos" | < 2.6.1 Search vendor "Cisco" for product "Fxos" and version " < 2.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 9300 Sm-36 Search vendor "Cisco" for product "Firepower 9300 Sm-36" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fxos Search vendor "Cisco" for product "Fxos" | < 2.6.1 Search vendor "Cisco" for product "Fxos" and version " < 2.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 9300 Sm-40 Search vendor "Cisco" for product "Firepower 9300 Sm-40" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fxos Search vendor "Cisco" for product "Fxos" | < 2.6.1 Search vendor "Cisco" for product "Fxos" and version " < 2.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 9300 Sm-44 Search vendor "Cisco" for product "Firepower 9300 Sm-44" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fxos Search vendor "Cisco" for product "Fxos" | < 2.6.1 Search vendor "Cisco" for product "Fxos" and version " < 2.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 9300 Sm-44 X 3 Search vendor "Cisco" for product "Firepower 9300 Sm-44 X 3" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fxos Search vendor "Cisco" for product "Fxos" | < 2.6.1 Search vendor "Cisco" for product "Fxos" and version " < 2.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 9300 Sm-48 Search vendor "Cisco" for product "Firepower 9300 Sm-48" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fxos Search vendor "Cisco" for product "Fxos" | < 2.6.1 Search vendor "Cisco" for product "Fxos" and version " < 2.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 9300 Sm-56 Search vendor "Cisco" for product "Firepower 9300 Sm-56" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fxos Search vendor "Cisco" for product "Fxos" | < 2.6.1 Search vendor "Cisco" for product "Fxos" and version " < 2.6.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 9300 Sm-56 X 3 Search vendor "Cisco" for product "Firepower 9300 Sm-56 X 3" | - | - |
Safe
|