CVE-2020-3391
published 2020-07-02CVE-2020-3391: A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text…
PriorityP339medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.31%
67.4th percentile
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to insecure storage of certain unencrypted credentials on an affected device. An attacker could exploit this vulnerability by viewing the network device configuration and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to discover and manage network devices.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_digital_network_architecture_center | — | — |
| cisco | digital_network_architecture_center | < 1.2.10 | 1.2.10 |
| cisco | digital_network_architecture_center | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_msrc7.5HIGH
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Digital Network Architecture Center Information Disclosure Vulnerability
vendor_cisco·2020-07-01·CVSS 6.5
CVE-2020-3391 [MEDIUM] CWE-200 Cisco Digital Network Architecture Center Information Disclosure Vulnerability
Cisco Digital Network Architecture Center Information Disclosure Vulnerability
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text.
The vulnerability is due to insecure storage of certain unencrypted credentials on an affected device. An attacker could exploit this vulnerability by viewing the network device configuration and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to discover and manage network devices.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.c
Microsoft
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
vendor_msrc·2020-01-14·CVSS 7.5
CVE-2020-0612 [HIGH] Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
Description: A denial of service vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the RD Gateway service on the target system to stop responding.
To exploit this vulnerability, an attacker would need to run a specially crafted application against a server which provides RD Gateway services.
The update addresses the vulnerability by correcting how RD Gateway handles connection requests.
FAQ: What network ports are vulnerable to this attack?
The vulnerability only affects UDP transport, which by default runs on UDP port 3391.
Windows
Cisco
Cisco Digital Network Architecture Center Information Disclosure Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3391 Cisco Digital Network Architecture Center Information Disclosure Vulnerability
CVE-2020-3391: Cisco Digital Network Architecture Center Information Disclosure Vulnerability
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to insecure storage of certain unencrypted credentials on an affected device. An attacker could exploit this vulnerability by viewing the network device configuration and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to discover and manage network devices. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-200, CWE-200
Bug IDs: CSCvn19092
GHSA
GHSA-jhv6-f622-9cgv: A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clea
ghsa_unreviewed·2022-05-24
CVE-2020-3391 [MEDIUM] CWE-522 GHSA-jhv6-f622-9cgv: A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clea
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to insecure storage of certain unencrypted credentials on an affected device. An attacker could exploit this vulnerability by viewing the network device configuration and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to discover and manage network devices.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-07-02
Published