CVE-2010-4302

Cisco Unified Videoconferencing System 5110 and 5115 - Weak Password Hashing in Mcu.val

Title source: llm
STIX 2.1

Description

/opt/rv/Versions/CurrentVersion/Mcu/Config/Mcu.val in Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, uses a weak hashing algorithm for the (1) administrator and (2) operator passwords, which makes it easier for local users to obtain sensitive information by recovering the cleartext values, aka Bug ID CSCti54010.

References (3)

Core 3
Core References
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2010/Nov/167

Scores

EPSS 0.0035
EPSS Percentile 27.8%

Details

CWE
CWE-310
Status published
Products (4)
cisco/unified_videoconferencing_system_5110
cisco/unified_videoconferencing_system_5110_firmware 7.0.1.13.3
cisco/unified_videoconferencing_system_5115
cisco/unified_videoconferencing_system_5115_firmware 7.0.1.13.3
Published Nov 22, 2010
Tracked Since Feb 18, 2026