PT-2020-4236 · Cisco · Cisco Data Center Network Manager

Published

2020-07-29

·

Updated

2020-08-05

·

CVE-2020-3376

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Cisco Data Center Network Manager (DCNM) (affected versions not specified)
Description: A vulnerability in the Device Manager application of Cisco Data Center Network Manager could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions on an affected device. The issue is due to a failure in the software to perform proper authentication for a critical function. An attacker could exploit this by browsing to one of the hosted URLs in Cisco DCNM, potentially allowing them to interact with and use certain functions within the Cisco DCNM.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04676
CVE-2020-3376

Affected Products

Cisco Data Center Network Manager