PT-2020-2899 · Cisco · Cisco Application Services Engine

Published

2020-06-03

·

Updated

2021-08-06

·

CVE-2020-3335

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Application Services Engine Software (affected versions not specified)
Description A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attacker to read sensitive information of other users on an affected device. The issue is due to insufficient authorization limitations. An attacker could exploit this by logging in to an affected device locally with valid credentials, potentially allowing them to read the sensitive information of other users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03056
CVE-2020-3335

Affected Products

Cisco Application Services Engine