CVE-2020-3377
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
31/07/2020
Last modified:
07/11/2023
Description
A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the affected device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted arguments to a specific field within the application. A successful exploit could allow the attacker to run commands as the administrator on the DCNM.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cisco:data_center_network_manager:11.0\(1\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:data_center_network_manager:11.1\(1\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:data_center_network_manager:11.2\(1\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:data_center_network_manager:11.3\(1\):*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



