PT-2020-4952 · Cisco · Cisco Iot Field Network Director
Billy Pierce
·
Published
2020-11-18
·
Updated
2020-11-25
·
CVE-2020-26075
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Cisco IoT Field Network Director (FND) (affected versions not specified)
Description:
A vulnerability in the REST API of Cisco IoT Field Network Director could allow an authenticated, remote attacker to gain access to the back-end database of an affected device. The issue is due to insufficient input validation of REST API requests. An attacker could exploit this by crafting malicious API requests to the affected device, potentially gaining access to the back-end database.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Iot Field Network Director