Description
Cisco CBOS 2.3.8 and earlier stores the passwords for (1) exec and (2) enable in cleartext in the NVRAM and a configuration file, which could allow unauthorized users to obtain the passwords and gain privileges.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/44544
Patch, Vendor Advisory vendor-advisory
x_refsource_cisco
http://www.cisco.com/warp/public/707/CBOS-multiple2-pub.html
Scores
EPSS
0.0116
EPSS Percentile
63.9%
Details
Status
published
Products (1)
cisco/cbos
< 2.3.8
Published
Oct 18, 2001
Tracked Since
Feb 18, 2026