Database/Control plane, storage & DevOps
Cisco UCS Central Software (weak backup encryption): Weak encryption on full-state and configuration backups means
Impact
Weak encryption on full-state and configuration backups means anyone who obtains a backup file recovers the sensitive information inside it - including the credentials UCS Central uses across the estate.
Who can reach it
Access to a UCS Central backup file. Backups routinely sit on shared file servers and in ticket attachments, which is what makes this practical.
What to do
Upgrade UCS Central per cisco-sa-ucsc-bkpsky-TgJ5f73J, then re-take backups and securely destroy old ones. Rotate credentials contained in previously-generated backups - the patch does not protect files already created.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.