CVE-2009-2977

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
27/08/2009
Last modified:
09/04/2025

Description

The Cisco Security Monitoring, Analysis and Response System (CS-MARS) 6.0.4 and earlier stores cleartext passwords in log/sysbacktrace.## files within error-logs.tar.gz archives, which allows context-dependent attackers to obtain sensitive information by reading these files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:cisco:cs-mars:*:*:*:*:*:*:*:* 6.0.4 (including)
cpe:2.3:h:cisco:cs-mars:4.1:*:*:*:*:*:*:*
cpe:2.3:h:cisco:cs-mars:4.1.2:*:*:*:*:*:*:*
cpe:2.3:h:cisco:cs-mars:4.1.3:*:*:*:*:*:*:*
cpe:2.3:h:cisco:cs-mars:4.1.5:*:*:*:*:*:*:*