CVE-2020-3139
published 2020-01-26CVE-2020-3139: A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Infrastructure Controller (APIC) could…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.04%
60.5th percentile
A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Infrastructure Controller (APIC) could allow an unauthenticated, remote attacker to bypass configured deny entries for specific IP ports. These IP ports would be permitted to the OOB management interface when, in fact, the packets should be dropped. The vulnerability is due to the configuration of specific IP table entries for which there is a programming logic error that results in the IP port being permitted. An attacker could exploit this vulnerability by sending traffic to the OOB management interface on the targeted device. A successful exploit could allow the attacker to bypass configured IP table rules to drop specific IP port traffic. The attacker has no control over the configuration of the device itself. This vulnerability affects Cisco APIC releases prior to the first fixed software Release 4.2(3j).
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | application_policy_infrastructure_controller | < 4.2\(3j\) | 4.2\(3j\) |
| cisco | application_policy_infrastructure_controller_out_of_band_management_ip_tables | — | — |
| cisco | cisco_application_policy_infrastructure_controller | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat8.1HIGH
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tcmu-runner: SCSI target (LIO) write to any block on ILO backstore
vendor_redhat·2021-01-13·CVSS 8.1
CVE-2021-3139 [HIGH] CWE-20 tcmu-runner: SCSI target (LIO) write to any block on ILO backstore
tcmu-runner: SCSI target (LIO) write to any block on ILO backstore
In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. NOTE: relative to CVE-2020-28374, this is a similar mistake in a different algorithm.
A flaw was found in the Linux kernel’s implementation of the Linux SCSI target host, where an authenticated attacker could write to any block on the exported SCSI device backing store. This flaw allows an authenticated attacker to send LIO block requests to the Linux system to overwrite data on the back
Cisco
Cisco Application Policy Infrastructure Controller Out Of Band Management IP Tables Bypass Vulnerability
vendor_cisco·2020-01-22·CVSS 5.3
CVE-2020-3139 [MEDIUM] CWE-20 Cisco Application Policy Infrastructure Controller Out Of Band Management IP Tables Bypass Vulnerability
Cisco Application Policy Infrastructure Controller Out Of Band Management IP Tables Bypass Vulnerability
A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Infrastructure Controller (APIC) could allow an unauthenticated, remote attacker to bypass configured deny entries for specific IP ports. These IP ports would be permitted to the OOB management interface when, in fact, the packets should be dropped.
The vulnerability is due to the configuration of specific IP table entries for which there is a programming logic error that results in the IP port being permitted. An attacker could exploit this vulnerability by sending traffic to the OOB management interface on the targeted device. A successful exploit could allow the atta
Cisco
Cisco Application Policy Infrastructure Controller Out Of Band Management IP Tables Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3139 Cisco Application Policy Infrastructure Controller Out Of Band Management IP Tables Bypass Vulnerability
CVE-2020-3139: Cisco Application Policy Infrastructure Controller Out Of Band Management IP Tables Bypass Vulnerability
A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Infrastructure Controller (APIC) could allow an unauthenticated, remote attacker to bypass configured deny entries for specific IP ports. These IP ports would be permitted to the OOB management interface when, in fact, the packets should be dropped. The vulnerability is due to the configuration of specific IP table entries for which there is a programming logic error that results in the IP port being permitted. An attacker could exploit this vulnerability by sending traffic to the OOB management interface on the targeted device. A successful exploit could a
GHSA
GHSA-j72w-hrcq-cmrg: [CVE-2020-3139_su] A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Infrastructure
ghsa_unreviewed·2022-05-24·CVSS 5.3
CVE-2020-3139 [MEDIUM] GHSA-j72w-hrcq-cmrg: [CVE-2020-3139_su] A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Infrastructure
[CVE-2020-3139_su] A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Infrastructure Controller (APIC) could allow an unauthenticated, remote attacker to bypass configured deny entries for specific IP ports. These IP ports would be permitted to the OOB management interface when, in fact, the packets should be dropped. The vulnerability is due to the configuration of specific IP table entries for which there is a programming logic error that results in the IP port being permitted. An attacker could exploit this vulnerability by sending traffic to the OOB management interface on the targeted device. A successful exploit could allow the attacker to bypass configured IP table rules to drop specific IP port traffic. The attacker
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-01-26
Published