PT-2020-3469 · Cisco · Cisco Data Center Network Manager
Published
2020-07-29
·
Updated
2020-08-05
·
CVE-2020-3382
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Data Center Network Manager (DCNM) versions prior to the fixed version
Description
The issue is related to the use of pre-installed credentials in the web interface of Cisco Data Center Network Manager (DCNM) and the REST API, which allows an unauthenticated, remote attacker to bypass authentication. The vulnerability exists due to the use of a static encryption key across different installations. An attacker could exploit this by crafting a valid session token using the static key, potentially allowing them to perform arbitrary actions with administrative privileges through the REST API.
Recommendations
For versions prior to the fixed version, update to the fixed version to resolve the issue.
As a temporary workaround, consider restricting access to the REST API to minimize the risk of exploitation.
Avoid using the static encryption key in the affected API endpoints until the issue is resolved.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Data Center Network Manager