CVE-2020-3335
Cisco Application Services Engine Software Authorization Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attacker to read sensitive information of other users on an affected device. The vulnerability is due to insufficient authorization limitations. An attacker could exploit this vulnerability by logging in to an affected device locally with valid credentials. A successful exploit could allow the attacker to read the sensitive information of other users on the affected device.
Una vulnerabilidad en el almacén de claves de Cisco Application Services Engine Software, podría permitir a un atacante local autenticado leer información confidencial de otros usuarios sobre un dispositivo afectado. La vulnerabilidad es debido a limitaciones de autorización insuficientes. Un atacante podría explotar esta vulnerabilidad al iniciar sesión localmente sobre un dispositivo afectado con credenciales válidas. Una explotación con éxito podría permitir al atacante leer la información confidencial de otros usuarios en el dispositivo afectado.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2019-12-12 CVE Reserved
- 2020-06-03 CVE Published
- 2023-03-08 EPSS Updated
- 2024-11-15 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-306: Missing Authentication for Critical Function
- CWE-863: Incorrect Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-APIC-KSV-3wzbHYT4 | 2021-08-06 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Application Policy Infrastructure Controller Search vendor "Cisco" for product "Application Policy Infrastructure Controller" | 1.1\(0c\) Search vendor "Cisco" for product "Application Policy Infrastructure Controller" and version "1.1\(0c\)" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Application Services Engine Search vendor "Cisco" for product "Application Services Engine" | < 1.1.2.20 Search vendor "Cisco" for product "Application Services Engine" and version " < 1.1.2.20" | - |
Affected
|