CVE-2020-8349
Summary
| CVE | CVE-2020-8349 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-14 22:15:00 UTC |
| Updated | 2020-10-29 19:52:00 UTC |
| Description | An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ optional REST API management interface. This interface is disabled by default and not vulnerable unless enabled. When enabled, it is only vulnerable where attached to a VRF and as allowed by defined ACLs. Lenovo strongly recommends upgrading to a non-vulnerable CNOS release. Where not possible, Lenovo recommends disabling the REST API management interface or restricting access to the management VRF and further limiting access to authorized management stations via ACL. |
Risk And Classification
Problem Types: CWE-94
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Lenovo | Cloud Networking Operating System | All | All | All | All |
| Operating System | Lenovo | Cloud Networking Operating System | All | All | All | All |
| Hardware | Lenovo | Rackswitch G8272 | - | All | All | All |
| Hardware | Lenovo | Rackswitch G8272 | - | All | All | All |
| Hardware | Lenovo | Rackswitch G8296 | - | All | All | All |
| Hardware | Lenovo | Rackswitch G8296 | - | All | All | All |
| Hardware | Lenovo | Rackswitch G8332 | - | All | All | All |
| Hardware | Lenovo | Rackswitch G8332 | - | All | All | All |
| Hardware | Lenovo | Rackswitch Ne0152t | - | All | All | All |
| Hardware | Lenovo | Rackswitch Ne0152t | - | All | All | All |
| Hardware | Lenovo | Rackswitch Ne10032 | - | All | All | All |
| Hardware | Lenovo | Rackswitch Ne10032 | - | All | All | All |
| Hardware | Lenovo | Rackswitch Ne1032 | - | All | All | All |
| Hardware | Lenovo | Rackswitch Ne1032 | - | All | All | All |
| Hardware | Lenovo | Rackswitch Ne1032t | - | All | All | All |
| Hardware | Lenovo | Rackswitch Ne1032t | - | All | All | All |
| Hardware | Lenovo | Rackswitch Ne1072t | - | All | All | All |
| Hardware | Lenovo | Rackswitch Ne1072t | - | All | All | All |
| Hardware | Lenovo | Rackswitch Ne2572 | - | All | All | All |
| Hardware | Lenovo | Rackswitch Ne2572 | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cloud Networking Operating System (CNOS) Vulnerability - Lenovo Support US | MISC | support.lenovo.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.