The Cisco Security Monitoring, Analysis and Response System (CS-MARS) 6.0.4 and earlier stores cleartext passwords in log/sysbacktrace.## files within error-logs.tar.gz archives, which allows context-dependent attackers to obtain sensitive information by reading these files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cs-mars | Cisco | * | 6.0.4 (including) |
Cs-mars | Cisco | 4.1 (including) | 4.1 (including) |
Cs-mars | Cisco | 4.1.2 (including) | 4.1.2 (including) |
Cs-mars | Cisco | 4.1.3 (including) | 4.1.3 (including) |
Cs-mars | Cisco | 4.1.5 (including) | 4.1.5 (including) |