cbcvebase.
CVE-2020-3411
published 2020-08-17

CVE-2020-3411: A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access to sensitive information on an affected system. The…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access to sensitive information on an affected system. The vulnerability is due to improper handling of authentication tokens by the affected software. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker access to sensitive device information, which includes configuration files.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscocatalyst_center>= 1.3 < 1.3.1.41.3.1.4
ciscocisco_digital_network_architecture_center
ciscodna_center