CVE-2020-3443

Severity
8.8HIGH
EPSS
0.8%
top 26.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 26
Latest updateMay 24

Description

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges and execute commands with higher privileges. The vulnerability is due to insufficient authorization of the System Operator role capabilities. An attacker could exploit this vulnerability by logging in with the System Operator role, performing a series of actions, and then assuming a new higher privileged role. A successful exploit could allow the attacker to p

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-f37p-j83j-rx9j: A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges and execute2022-05-24
CVEList
Cisco Smart Software Manager On-Prem Privilege Escalation Vulnerability2020-08-26

📋Vendor Advisories

1
Cisco
Cisco Smart Software Manager On-Prem Privilege Escalation Vulnerability2020-08-19
CVE-2020-3443 (HIGH CVSS 8.8) | A vulnerability in Cisco Smart Soft | cvebase.io