PT-2020-4964 · Cisco · Cisco Dna Spaces Connector

Published

2020-11-18

·

Updated

2020-12-02

·

CVE-2020-3586

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco DNA Spaces Connector (affected versions not specified)
Description A vulnerability in the web-based management interface of Cisco DNA Spaces Connector could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The issue is due to insufficient validation of user-supplied input in the web-based management interface. An attacker could exploit this by sending crafted HTTP requests to the interface. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with privileges of the web-based management application, potentially impacting the integrity or availability of the application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05540
CVE-2020-3586

Affected Products

Cisco Dna Spaces Connector