PT-2020-1734 · Cisco · Cisco Data Center Network Manager
Sven Krewitt
·
Published
2020-02-19
·
Updated
2020-02-24
·
CVE-2020-3112
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Data Center Network Manager (DCNM) (affected versions not specified)
Description
The issue is related to errors in privilege management in the REST API interface of the Cisco Data Center Network Manager (DCNM) system. It could allow a remote attacker to elevate their privileges on the application due to insufficient access control validation. An attacker could exploit this by authenticating with a low-privilege account and sending a crafted request to the API, potentially allowing them to interact with the API with administrative privileges.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Data Center Network Manager