5.8
CVSSv2

CVE-2020-3597

Published: 08/10/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.4 | Impact Score: 2.5 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

A vulnerability in the configuration restore feature of Cisco Nexus Data Broker software could allow an unauthenticated, remote malicious user to perform a directory traversal attack on an affected device. The vulnerability is due to insufficient validation of configuration backup files. An attacker could exploit this vulnerability by persuading an administrator to restore a crafted configuration backup file. A successful exploit could allow the malicious user to overwrite arbitrary files that are accessible through the affected software on an affected device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco nexus data broker

Vendor Advisories

A vulnerability in the configuration restore feature of Cisco Nexus Data Broker software could allow an unauthenticated, remote attacker to perform a directory traversal attack on an affected device The vulnerability is due to insufficient validation of configuration backup files An attacker could exploit this vulnerability by persuading an admin ...