CVE-2009-2977
Severity CVSS v4.0:
Pending analysis
Type:
CWE-310
Cryptographic Issues
Publication date:
27/08/2009
Last modified:
09/04/2025
Description
The Cisco Security Monitoring, Analysis and Response System (CS-MARS) 6.0.4 and earlier stores cleartext passwords in log/sysbacktrace.## files within error-logs.tar.gz archives, which allows context-dependent attackers to obtain sensitive information by reading these files.
Impact
Base Score 2.0
3.30
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:h:cisco:cs-mars:*:*:*:*:*:*:*:* | 6.0.4 (including) | |
| cpe:2.3:h:cisco:cs-mars:4.1:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:cs-mars:4.1.2:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:cs-mars:4.1.3:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:cs-mars:4.1.5:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCtb52450
- http://www.securityfocus.com/archive/1/505995/100/0/threaded
- http://www.securityfocus.com/archive/1/505998/100/0/threaded
- http://www.securityfocus.com/bid/36098
- http://www.vupen.com/english/advisories/2009/2364
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52913
- http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCtb52450
- http://www.securityfocus.com/archive/1/505995/100/0/threaded
- http://www.securityfocus.com/archive/1/505998/100/0/threaded
- http://www.securityfocus.com/bid/36098
- http://www.vupen.com/english/advisories/2009/2364
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52913



