PT-2020-3772 · Cisco · Cisco Smart Software Manager On-Prem
Published
2020-08-19
·
Updated
2020-09-02
·
CVE-2020-3443
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Cisco Smart Software Manager On-Prem (affected versions not specified)
Description:
A vulnerability in Cisco Smart Software Manager On-Prem could allow an authenticated, remote attacker to elevate privileges and execute commands with higher privileges. The issue is due to insufficient authorization of the System Operator role capabilities. An attacker could exploit this by logging in with the System Operator role, performing a series of actions, and then assuming a new higher privileged role. A successful exploit could allow the attacker to perform all actions associated with the privilege of the assumed role, potentially gaining full access to the device if the assumed role is administrative.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Smart Software Manager On-Prem