CVE-2018-15407

MEDIUM

Cisco Hyperflex HX Data Platform - Information Disclosure

Title source: rule
STIX 2.1

Description

A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information. The vulnerability is due to insufficient cleanup of installation files. An attacker could exploit this vulnerability by accessing the residual installation files on an affected system. A successful exploit could allow the attacker to collect sensitive information regarding the configuration of the system.

Scores

CVSS v3 5.5
EPSS 0.0006
EPSS Percentile 18.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-459
Status published
Products (1)
cisco/hyperflex_hx_data_platform 3.0\(1a\)
Published Oct 05, 2018
Tracked Since Feb 18, 2026