CVE-2020-3567
Summary
| CVE | CVE-2020-3567 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-08 05:15:00 UTC |
| Updated | 2023-11-07 03:22:00 UTC |
| Description | A vulnerability in the management REST API of Cisco Industrial Network Director (IND) could allow an authenticated, remote attacker to cause the CPU utilization to increase to 100 percent, resulting in a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of requests sent to the REST API. An attacker could exploit this vulnerability by sending a crafted request to the REST API. A successful exploit could allow the attacker to cause a permanent DoS condition that is due to high CPU utilization. Manual intervention may be required to recover the Cisco IND. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Industrial Network Director | All | All | All | All |
| Application | Cisco | Industrial Network Director | All | All | All | All |
| Application | Cisco | Network Level Service | 1.8\(0.142\) | All | All | All |
| Application | Cisco | Network Level Service | 1.9\(0.63\) | All | All | All |
| Application | Cisco | Network Level Service | 1.8\(0.142\) | All | All | All |
| Application | Cisco | Network Level Service | 1.9\(0.63\) | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Industrial Network Director Denial of Service Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.