CVE-2020-3392
published 2020-11-18CVE-2020-3392: A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on an…
PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.53%
72.1th percentile
A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on an affected system. The vulnerability exists because the affected software does not properly authenticate API calls. An attacker could exploit this vulnerability by sending API requests to an affected system. A successful exploit could allow the attacker to view sensitive information on the affected system, including information about the devices that the system manages, without authentication.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_iot_field_network_director | — | — |
| cisco | iot_field_network_director | < 4.6.1 | 4.6.1 |
| cisco | iot_field_network_director_missing | — | — |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.37 | 1:2.11+dfsg-1ubuntu7.37 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.17 | 1:4.2-3ubuntu6.17 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv2.3LOW
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vc2p-5mxr-hx98: A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on
ghsa_unreviewed·2022-05-24
CVE-2020-3392 [HIGH] CWE-306 GHSA-vc2p-5mxr-hx98: A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on
A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on an affected system. The vulnerability exists because the affected software does not properly authenticate API calls. An attacker could exploit this vulnerability by sending API requests to an affected system. A successful exploit could allow the attacker to view sensitive information on the affected system, including information about the devices that the system manages, without authentication.
OSV
qemu vulnerabilities
osv·2021-07-15·CVSS 2.3
CVE-2020-15469 qemu vulnerabilities
qemu vulnerabilities
Lei Sun discovered that QEMU incorrectly handled certain MMIO operations.
An attacker inside the guest could possibly use this issue to cause QEMU to
crash, resulting in a denial of service. (CVE-2020-15469)
Wenxiang Qian discovered that QEMU incorrectly handled certain ATAPI
commands. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. This issue only
affected Ubuntu 21.04. (CVE-2020-29443)
Cheolwoo Myung discovered that QEMU incorrectly handled SCSI device
emulation. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2020-35504,
CVE-2020-35505, CVE-2021-3392)
Alex Xu discovered that QEMU incorrectly handled the virtio-fs shared f
Cisco
Cisco IoT Field Network Director Missing API Authentication Vulnerability
vendor_cisco·2020-11-18·CVSS 7.5
CVE-2020-3392 [HIGH] CWE-306 Cisco IoT Field Network Director Missing API Authentication Vulnerability
Cisco IoT Field Network Director Missing API Authentication Vulnerability
A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on an affected system.
The vulnerability exists because the affected software does not properly authenticate API calls. An attacker could exploit this vulnerability by sending API requests to an affected system. A successful exploit could allow the attacker to view sensitive information on the affected system, including information about the devices that the system manages, without authentication.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
Cisco
Cisco IoT Field Network Director Missing API Authentication Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3392 Cisco IoT Field Network Director Missing API Authentication Vulnerability
CVE-2020-3392: Cisco IoT Field Network Director Missing API Authentication Vulnerability
A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on an affected system. The vulnerability exists because the affected software does not properly authenticate API calls. An attacker could exploit this vulnerability by sending API requests to an affected system. A successful exploit could allow the attacker to view sensitive information on the affected system, including information about the devices that the system manages, without authentication. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-306, CWE-306
Bug IDs: CSCvt45296
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-11-18
Published