cbcvebase.
CVE-2020-3531
published 2020-11-18

CVE-2020-3531: A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to access the back-end database of an…

PriorityP268critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.17%
80.2th percentile
A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to access the back-end database of an affected system. The vulnerability exists because the affected software does not properly authenticate REST API calls. An attacker could exploit this vulnerability by obtaining a cross-site request forgery (CSRF) token and then using the token with REST API requests. A successful exploit could allow the attacker to access the back-end database of the affected device and read, alter, or drop information.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscocisco_iot_field_network_director
ciscoiot_field_network_director< 4.6.14.6.1
ciscoiot_field_network_director_unauthenticated_rest

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit requires first obtaining a CSRF token, then using it with unauthenticated REST API requests to access the back-end database — monitor for REST API calls carrying CSRF tokens that are not associated with an authenticated session.
  • Track Cisco bug IDs CSCvt45219 and CSCvt45228 for patch status and vendor threat intelligence updates related to this vulnerability.
  • ·There are no workarounds available for this vulnerability; the only remediation is applying the vendor-released software update.
  • ·The vulnerability is classified under CWE-306 (Missing Authentication for Critical Function), meaning any REST API endpoint in Cisco FND that lacks proper authentication enforcement is potentially in scope.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.