Rewterz Threat Advisory – Multiple Vulnerabilities in F5’s BIG-IP Allow Full System Compromise
July 3, 2020Rewterz Threat Advisory – CVE-2020-8477 – ICS: ABB System 800xA Information Manager
July 3, 2020Rewterz Threat Advisory – Multiple Vulnerabilities in F5’s BIG-IP Allow Full System Compromise
July 3, 2020Rewterz Threat Advisory – CVE-2020-8477 – ICS: ABB System 800xA Information Manager
July 3, 2020Severity
Medium
Analysis Summary
The vulnerability is due to insecure storage of certain unencrypted credentials on an affected device. An attacker could exploit this vulnerability by viewing the network device configuration and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to discover and manage network devices.
Impact
Information Disclosure
Affected Vendors
Cisco
Affected Products
Cisco DNA Center releases earlier than Release 1.2.10
Remediation
Refer to Cisco advisory for the list of affected products and upgraded patches.