PT-2020-2893 · Cisco · Cisco Dna Center

Published

2020-06-03

·

Updated

2020-06-11

·

CVE-2020-3281

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Digital Network Architecture (DNA) Center (affected versions not specified)
Description A vulnerability in the audit logging component could allow an authenticated, remote attacker to view sensitive information in clear text. This is due to the storage of certain unencrypted credentials. An attacker could exploit this by accessing the audit logs and obtaining credentials they may not normally have access to, potentially allowing them to discover and manage network devices.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insertion into Log File

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03050
CVE-2020-3281

Affected Products

Cisco Dna Center