CVE-2018-15407

MEDIUM

Cisco HyperFlex HX Data Platform - Authenticated Sensitive Information Exposure via Residual Installation Files

Title source: llm
STIX 2.1

Description

A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information. The vulnerability is due to insufficient cleanup of installation files. An attacker could exploit this vulnerability by accessing the residual installation files on an affected system. A successful exploit could allow the attacker to collect sensitive information regarding the configuration of the system.

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0029
EPSS Percentile 20.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-459
Status published
Products (1)
cisco/hyperflex_hx_data_platform 3.0\(1a\)
Published Oct 05, 2018
Tracked Since Feb 18, 2026