PT-2020-4952 · Cisco · Cisco Iot Field Network Director

Billy Pierce

·

Published

2020-11-18

·

Updated

2020-11-25

·

CVE-2020-26075

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Cisco IoT Field Network Director (FND) (affected versions not specified)
Description: A vulnerability in the REST API of Cisco IoT Field Network Director could allow an authenticated, remote attacker to gain access to the back-end database of an affected device. The issue is due to insufficient input validation of REST API requests. An attacker could exploit this by crafting malicious API requests to the affected device, potentially gaining access to the back-end database.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05527
CVE-2020-26075

Affected Products

Cisco Iot Field Network Director