CVE-2020-3281
published 2020-06-03CVE-2020-3281: A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view…
PriorityP351high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.05%
60.4th percentile
A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to discover and manage network devices.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_digital_network_architecture_center | — | — |
| cisco | digital_network_architecture_center | < 1.3.3.3 | 1.3.3.3 |
| cisco | digital_network_architecture_center | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Digital Network Architecture Center Information Disclosure Vulnerability
vendor_cisco·2020-06-03·CVSS 4.3
CVE-2020-3281 [MEDIUM] CWE-532 Cisco Digital Network Architecture Center Information Disclosure Vulnerability
Cisco Digital Network Architecture Center Information Disclosure Vulnerability
A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text.
The vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to discover and manage network devices.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.cloudapps.cis
Cisco
Cisco Digital Network Architecture Center Information Disclosure Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3281 Cisco Digital Network Architecture Center Information Disclosure Vulnerability
CVE-2020-3281: Cisco Digital Network Architecture Center Information Disclosure Vulnerability
A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to discover and manage network devices. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-532, CWE-532
Bug IDs: CSCvs65165
GHSA
GHSA-hcrf-j785-xgwj: A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to vie
ghsa_unreviewed·2022-05-24
CVE-2020-3281 [HIGH] CWE-532 GHSA-hcrf-j785-xgwj: A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to vie
A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to discover and manage network devices.
No detection rules found.
No public exploits indexed.
2020-06-03
Published