4.3
CVSSv2

CVE-2020-3261

Published: 15/04/2020 Updated: 29/04/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A vulnerability in the web-based management interface of Cisco Mobility Express Software could allow an unauthenticated, remote malicious user to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user with an active session on an affected device to follow a malicious link. A successful exploit could allow the malicious user to perform arbitrary actions, including modifying the configuration, with the privilege level of the user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco aironet 1542i firmware

cisco aironet 1542i firmware 8.10(1.255)

cisco aironet 1542d firmware

cisco aironet 1542d firmware 8.10(1.255)

cisco aironet 1562i firmware

cisco aironet 1562i firmware 8.10(1.255)

cisco aironet 1562e firmware

cisco aironet 1562e firmware 8.10(1.255)

cisco aironet 1562d firmware

cisco aironet 1562d firmware 8.10(1.255)

cisco aironet 1815 firmware

cisco aironet 1815 firmware 8.10(1.255)

cisco aironet 1830 firmware

cisco aironet 1830 firmware 8.10(1.255)

cisco aironet 1840 firmware

cisco aironet 1840 firmware 8.10(1.255)

cisco aironet 1850 firmware

cisco aironet 1850 firmware 8.10(1.255)

cisco aironet 2800i firmware

cisco aironet 2800i firmware 8.10(1.255)

cisco aironet 2800e firmware

cisco aironet 2800e firmware 8.10(1.255)

cisco aironet 3800i firmware

cisco aironet 3800i firmware 8.10(1.255)

cisco aironet 3800e firmware

cisco aironet 3800e firmware 8.10(1.255)

cisco aironet 3800p firmware

cisco aironet 3800p firmware 8.10(1.255)

cisco aironet 4800 firmware

cisco aironet 4800 firmware 8.10(1.255)

cisco catalyst iw6300 firmware

cisco catalyst iw6300 firmware 8.10(1.255)

cisco 6300 series access points firmware

cisco 6300 series access points firmware 8.10(1.255)

Vendor Advisories

A vulnerability in the web-based management interface of Cisco Mobility Express Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device An attacker coul ...