Cisco CBOS 2.3.8 and earlier stores the passwords for (1) exec and (2) enable in cleartext in the NVRAM and a configuration file, which could allow unauthorized users to obtain the passwords and gain privileges.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/44544 | vdb entry |
http://www.cisco.com/warp/public/707/CBOS-multiple2-pub.html | patch vendor advisory |