CVE-2020-3140
Cisco Prime License Manager Privilege Escalation Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the web management interface of Cisco Prime License Manager (PLM) Software could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient validation of user input on the web management interface. An attacker could exploit this vulnerability by submitting a malicious request to an affected system. An exploit could allow the attacker to gain administrative-level privileges on the system. The attacker needs a valid username to exploit this vulnerability.
Una vulnerabilidad en la interfaz de administración web de Cisco Prime License Manager (PLM) Software, podría permitir a un atacante remoto no autenticado obtener acceso no autorizado hacia un dispositivo afectado. La vulnerabilidad es debido a una comprobación de entrada insuficiente del usuario en la interfaz de administración web. Un atacante podría explotar esta vulnerabilidad mediante el envío de una petición maliciosa hacia un sistema afectado. Un explotación podría permitir a un atacante obtener privilegios de nivel administrativo en el sistema. El atacante necesita un nombre de usuario válido para explotar esta vulnerabilidad
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2019-12-12 CVE Reserved
- 2020-07-16 CVE Published
- 2024-08-24 EPSS Updated
- 2024-11-15 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-255: Credentials Management Errors
- CWE-863: Incorrect Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Prime License Manager Search vendor "Cisco" for product "Prime License Manager" | <= 10.5\(2\)su9 Search vendor "Cisco" for product "Prime License Manager" and version " <= 10.5\(2\)su9" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Prime License Manager Search vendor "Cisco" for product "Prime License Manager" | >= 11.0 <= 11.5\(1\)su6 Search vendor "Cisco" for product "Prime License Manager" and version " >= 11.0 <= 11.5\(1\)su6" | - |
Affected
|