Vulnerability Bulletins

Cisco UCS Invicta Software Default GPG Key Vulnerability

   
Affected software Cisco
 
A vulnerability in Cisco UCS Invicta Software could allow an unauthenticated, remote attacker to access some encrypted information, if the attacker can intercept communication between an affected system and a Cisco UCS Invicta Autosupport server.The vulnerability is due to the presence of a default, static encryption key in the affected software. The key is used to encrypt some of the information that is exchanged between an affected device and the Autosupport server. An attacker could exploit

More info:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160524-ucs-inv?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20UCS%20Invicta%20Software%20Default%20GPG%20Key%20Vulnerability&vs_