The Cisco AMP For Endpoints application allows an authenticated, local attacker to access a static key value stored in the local application software. The vulnerability is due to the use of a static key value stored in the application used to encrypt the connector protection password. An attacker could exploit this vulnerability by gaining local, administrative access to a Windows host and stopping the Cisco AMP for Endpoints service. Cisco Bug IDs: CSCvg42904.
The product contains hard-coded credentials, such as a password or cryptographic key.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Advanced_malware_protection | Cisco | 3.1(10) (including) | 3.1(10) (including) |
Advanced_malware_protection | Cisco | 3.1(15) (including) | 3.1(15) (including) |
Advanced_malware_protection | Cisco | 4.0(0) (including) | 4.0(0) (including) |
Advanced_malware_protection | Cisco | 4.0(1) (including) | 4.0(1) (including) |
Advanced_malware_protection | Cisco | 4.0(2) (including) | 4.0(2) (including) |
Advanced_malware_protection | Cisco | 4.1(0) (including) | 4.1(0) (including) |
Advanced_malware_protection | Cisco | 4.1(1) (including) | 4.1(1) (including) |
Advanced_malware_protection | Cisco | 4.1(4) (including) | 4.1(4) (including) |
Advanced_malware_protection | Cisco | 4.2(0) (including) | 4.2(0) (including) |
Advanced_malware_protection | Cisco | 4.2(1) (including) | 4.2(1) (including) |
Advanced_malware_protection | Cisco | 4.3(0) (including) | 4.3(0) (including) |
Advanced_malware_protection | Cisco | 4.3(1) (including) | 4.3(1) (including) |
Advanced_malware_protection | Cisco | 4.4(0) (including) | 4.4(0) (including) |
Advanced_malware_protection | Cisco | 4.4(1) (including) | 4.4(1) (including) |
Advanced_malware_protection | Cisco | 4.4(2) (including) | 4.4(2) (including) |
Advanced_malware_protection | Cisco | 4.4(4) (including) | 4.4(4) (including) |
Advanced_malware_protection | Cisco | 5.0(1) (including) | 5.0(1) (including) |
Advanced_malware_protection | Cisco | 5.0(3) (including) | 5.0(3) (including) |
Advanced_malware_protection | Cisco | 5.0(5) (including) | 5.0(5) (including) |
Advanced_malware_protection | Cisco | 5.0(7) (including) | 5.0(7) (including) |
Advanced_malware_protection | Cisco | 5.0(9) (including) | 5.0(9) (including) |
Advanced_malware_protection | Cisco | 5.1(1) (including) | 5.1(1) (including) |
Advanced_malware_protection | Cisco | 5.1(3) (including) | 5.1(3) (including) |
Advanced_malware_protection | Cisco | 5.1(5) (including) | 5.1(5) (including) |
Advanced_malware_protection | Cisco | 5.1(7) (including) | 5.1(7) (including) |
Advanced_malware_protection | Cisco | 5.1(9) (including) | 5.1(9) (including) |
Advanced_malware_protection | Cisco | 5.1(11) (including) | 5.1(11) (including) |
Advanced_malware_protection | Cisco | 5.1(13) (including) | 5.1(13) (including) |
Advanced_malware_protection | Cisco | 6.0(1) (including) | 6.0(1) (including) |
There are two main variations: