Cisco Bug: CSCuj84274 - UCS-B IPMI RAKP allows remote attackers to obtain password hashes
Nov 14, 2020
- Cisco Unified Computing System
Known Affected Releases
Symptom: A vulnerability in the Cisco Integrated Management Controller (CIMC) on the Cisco Unified Computing System Series Platforms could allow an unauthenticated, remote attacker to obtain the password hashes residing on the affected device. The vulnerability is due to the implementation of an insecure authentication protocol. An attacker could exploit this vulnerability by sending a crafted packet to the CIMC of an affected device. An exploit could allow the attacker to receive a response from the CIMC that contains an RKMP message that will allow an attacker to obtain the password hashes for the system that can then be used in an offline cracking attack. Conditions: Device configured with the IPMI interface enabled.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.
Bug Details Include
- Full Description (including symptoms, conditions and workarounds)
- Known Fixed Releases
- Related Community Discussions
- Number of Related Support Cases