PT-2020-3066 · Cisco · Cisco Digital Network Architecture (Dna) Center

Published

2020-07-02

·

Updated

2021-08-06

·

CVE-2020-3391

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Digital Network Architecture (DNA) Center (affected versions not specified)
Description A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The issue is due to insecure storage of certain unencrypted credentials on an affected device. An attacker could exploit this by viewing the network device configuration and obtaining credentials they may not normally have access to, potentially allowing them to discover and manage network devices.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03357
CVE-2020-3391

Affected Products

Cisco Digital Network Architecture (Dna) Center