← back
CVE-2020-3382

Cisco Data Center Network Manager Authentication Bypass Vulnerability

CVSS 9.8 CRITICALEPSS 2.3%CWE-798
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.8EPSS 2.3%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
31 Jul 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability in the REST API of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability exists because different installations share a static encryption key. An attacker could exploit this vulnerability by using the static key to craft a valid session token. A successful exploit could allow the attacker to perform arbitrary actions through the REST API with administrative privileges.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →