8.8
CVSSv3

CVE-2020-3377

Published: 31/07/2020 Updated: 07/11/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote malicious user to inject arbitrary commands on the affected device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted arguments to a specific field within the application. A successful exploit could allow the malicious user to run commands as the administrator on the DCNM.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco data center network manager 11.0\\(1\\)

cisco data center network manager 11.1\\(1\\)

cisco data center network manager 11.2\\(1\\)

cisco data center network manager 11.3\\(1\\)

Vendor Advisories

A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the affected device The vulnerability is due to insufficient validation of user-supplied input An attacker could exploit this vulnerability by sending crafted arguments to a sp ...