6.5
CVSSv3

CVE-2020-3567

Published: 08/10/2020 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C

Vulnerability Summary

A vulnerability in the management REST API of Cisco Industrial Network Director (IND) could allow an authenticated, remote malicious user to cause the CPU utilization to increase to 100 percent, resulting in a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of requests sent to the REST API. An attacker could exploit this vulnerability by sending a crafted request to the REST API. A successful exploit could allow the malicious user to cause a permanent DoS condition that is due to high CPU utilization. Manual intervention may be required to recover the Cisco IND.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco network level service 1.8\\(0.142\\)

cisco industrial network director

cisco network level service 1.9\\(0.63\\)

Vendor Advisories

A vulnerability in the management REST API of Cisco Industrial Network Director (IND) could allow an authenticated, remote attacker to cause the CPU utilization to increase to 100 percent, resulting in a denial of service (DoS) condition on an affected device The vulnerability is due to insufficient validation of requests sent to the REST API An ...