cbcvebase.
CVE-2020-3392
published 2020-11-18

CVE-2020-3392: A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on an…

PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.53%
71.8th percentile
A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on an affected system. The vulnerability exists because the affected software does not properly authenticate API calls. An attacker could exploit this vulnerability by sending API requests to an affected system. A successful exploit could allow the attacker to view sensitive information on the affected system, including information about the devices that the system manages, without authentication.

Affected

5 ranges
VendorProductVersion rangeFixed in
ciscocisco_iot_field_network_director
ciscoiot_field_network_director< 4.6.14.6.1
ciscoiot_field_network_director_missing
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.371:2.11+dfsg-1ubuntu7.37
qemuqemu>= 0 < 1:4.2-3ubuntu6.171:4.2-3ubuntu6.17

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv2.3LOW
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.