CVE-2020-3242
Published on: 06/17/2020 12:00:00 AM UTC
Last Modified on: 09/17/2021 06:52:00 PM UTC
CVE-2020-3242 - advisory for cisco-sa-ucsd-info-disclosure-gSMU8EKT
Source: Mitre Source: NIST CVE.ORG Print: PDF
Certain versions of Ucs Director from Cisco contain the following vulnerability:
A vulnerability in the REST API of Cisco UCS Director could allow an authenticated, remote attacker with administrative privileges to obtain confidential information from an affected device. The vulnerability exists because confidential information is returned as part of an API response. An attacker could exploit this vulnerability by sending a crafted request to the API. A successful exploit could allow the attacker to obtain the API key of another user, which would allow the attacker to impersonate the account of that user on the affected device. To exploit this vulnerability, the attacker must have administrative privileges on the device.
- CVE-2020-3242 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.
- Affected Vendor/Software:
Cisco - Cisco Unified Computing System (Management Software) version n/a
CVSS3 Score: 4.9 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | HIGH | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVSS2 Score: 4 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Cisco UCS Director Information Disclosure Vulnerability | Vendor Advisory tools.cisco.com text/html |
![]() |
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Cisco | Ucs Director | All | All | All | All |
Application | Cisco | Ucs Director | All | All | All | All |
- cpe:2.3:a:cisco:ucs_director:*:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:ucs_director:*:*:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|