CVE-2020-3365

CWE-22Path Traversal5 documents5 sources
Severity
6.5MEDIUM
EPSS
0.3%
top 44.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 4
Latest updateMay 24

Description

A vulnerability in the directory permissions of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform a directory traversal attack on a limited set of restricted directories. The vulnerability is due to a flaw in the logic that governs directory permissions. An attacker could exploit this vulnerability by using capabilities that are not controlled by the role-based access control (RBAC) mechanisms of the software. A successful exploit could

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

🔴Vulnerability Details

2
GHSA
GHSA-3p39-2wh4-rwfp: A vulnerability in the directory permissions of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to2022-05-24
CVEList
Cisco Enterprise NFV Infrastructure Software Path Traversal Vulnerability2020-09-04

📋Vendor Advisories

1
Cisco
Cisco Enterprise NFV Infrastructure Software Path Traversal Vulnerability2020-09-02

💬Community

1
Bugzilla
CVE-2020-15810 squid: HTTP Request Smuggling could result in cache poisoning2020-08-24
CVE-2020-3365 (MEDIUM CVSS 6.5) | A vulnerability in the directory pe | cvebase.io