PT-2020-3890 · Cisco · Cisco Data Center Network Manager

Published

2020-07-15

·

Updated

2020-07-22

·

CVE-2020-3380

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Cisco Data Center Network Manager (DCNM) (affected versions not specified)
Description: A vulnerability in the CLI of Cisco Data Center Network Manager could allow an authenticated, local attacker to elevate privileges to root and execute arbitrary commands on the underlying operating system. The issue is due to insufficient restrictions during the execution of an affected CLI command. An attacker could exploit this by authenticating as the fmserver user and submitting malicious input to a specific command, potentially allowing them to elevate privileges and execute arbitrary commands.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04283
CVE-2020-3380

Affected Products

Cisco Data Center Network Manager