Classic Cisco IOS 9.1 and later allows attackers with access to the login prompt to obtain portions of the command history of previous users, which may allow the attacker to access sensitive data.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.ciac.org/ciac/bulletins/j-009.shtml | third party advisory patch government resource vendor advisory |
http://www.cisco.com/warp/public/770/ioshist-pub.shtml | patch vendor advisory |