CVE-2020-3567
published 2020-10-08CVE-2020-3567: A vulnerability in the management REST API of Cisco Industrial Network Director (IND) could allow an authenticated, remote attacker to cause the CPU…
PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.15%
63.3th percentile
A vulnerability in the management REST API of Cisco Industrial Network Director (IND) could allow an authenticated, remote attacker to cause the CPU utilization to increase to 100 percent, resulting in a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of requests sent to the REST API. An attacker could exploit this vulnerability by sending a crafted request to the REST API. A successful exploit could allow the attacker to cause a permanent DoS condition that is due to high CPU utilization. Manual intervention may be required to recover the Cisco IND.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_industrial_network_director | — | — |
| cisco | industrial_network_director | < 1.9.0 | 1.9.0 |
| cisco | industrial_network_director | — | — |
| cisco | network_level_service | — | — |
| cisco | network_level_service | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
vendor_redhat7.8HIGH
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5vp7-f4x6-7r58: A vulnerability in the management REST API of Cisco Industrial Network Director (IND) could allow an authenticated, remote attacker to cause the CPU u
ghsa_unreviewed·2022-05-24
CVE-2020-3567 [MEDIUM] CWE-20 GHSA-5vp7-f4x6-7r58: A vulnerability in the management REST API of Cisco Industrial Network Director (IND) could allow an authenticated, remote attacker to cause the CPU u
A vulnerability in the management REST API of Cisco Industrial Network Director (IND) could allow an authenticated, remote attacker to cause the CPU utilization to increase to 100 percent, resulting in a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of requests sent to the REST API. An attacker could exploit this vulnerability by sending a crafted request to the REST API. A successful exploit could allow the attacker to cause a permanent DoS condition that is due to high CPU utilization. Manual intervention may be required to recover the Cisco IND.
Red Hat
caribou: segfault on pressing ē since Xorg CVE-2020-25712 fix
vendor_redhat·2021-01-13·CVSS 7.8
CVE-2021-3567 [HIGH] CWE-787 caribou: segfault on pressing ē since Xorg CVE-2020-25712 fix
caribou: segfault on pressing ē since Xorg CVE-2020-25712 fix
A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applications that leverage Caribou as an input mechanism. The highest threat from this vulnerability is to system availability.
A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applications that leverage Caribou as an input mechanism. The highest threat from this vulnerability is to system availability.
Package: caribou (Red Hat Enterprise Linux 7) - Out of support scope
Cisco
Cisco Industrial Network Director Denial of Service Vulnerability
vendor_cisco·2020-10-07·CVSS 6.5
CVE-2020-3567 [MEDIUM] CWE-20 Cisco Industrial Network Director Denial of Service Vulnerability
Cisco Industrial Network Director Denial of Service Vulnerability
A vulnerability in the management REST API of Cisco Industrial Network Director (IND) could allow an authenticated, remote attacker to cause the CPU utilization to increase to 100 percent, resulting in a denial of service (DoS) condition on an affected device.
The vulnerability is due to insufficient validation of requests sent to the REST API. An attacker could exploit this vulnerability by sending a crafted request to the REST API. A successful exploit could allow the attacker to cause a permanent DoS condition that is due to high CPU utilization. Manual intervention may be required to recover the Cisco IND.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vu
Cisco
Cisco Industrial Network Director Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2020-3567 Cisco Industrial Network Director Denial of Service Vulnerability
CVE-2020-3567: Cisco Industrial Network Director Denial of Service Vulnerability
A vulnerability in the management REST API of Cisco Industrial Network Director (IND) could allow an authenticated, remote attacker to cause the CPU utilization to increase to 100 percent, resulting in a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of requests sent to the REST API. An attacker could exploit this vulnerability by sending a crafted request to the REST API. A successful exploit could allow the attacker to cause a permanent DoS condition that is due to high CPU utilization. Manual intervention may be required to recover the Cisco IND. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-10-08
Published