← back
CVE-2020-26077

Cisco IoT Field Network Director Improper Access Control Vulnerability

CVSS 5 MEDIUMEPSS 0.7%CWE-284
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5EPSS 0.7%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
18 Nov 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability in the access control functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to view lists of users from different domains that are configured on an affected system. The vulnerability is due to improper access control. An attacker could exploit this vulnerability by sending an API request that alters the domain for a requested user list on an affected system. A successful exploit could allow the attacker to view lists of users from different domains on the affected system.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →