Vulnslist

find the latest Cisco vulnerabilities

Cisco DNA Spaces Connector Command Injection Vulnerability

cisco-sa-dna-cmd-injection-rrAYzOwc · Critical · Published · Updated

A vulnerability in the web-based management interface of Cisco DNA Spaces Connector could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient validation of user-supplied input in the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on the underling operating system with privileges of the web-based management application, which is running as a restricted user. This could result in changes being made to pages served by the web-based management application impacting the integrity or availability of the web-based management application. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dna-cmd-injection-rrAYzOwc

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2020-3586
Cisco Bug IDsCSCvv25495
CVSS ScoreBase 9.4
Base 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco DNA Spaces Connector

CSAF Product Statuses

Product Status Source CVE Rows
Cisco DNA Spaces Connector known_affected cisco_csaf CVE-2020-3586 1

Related Products

Product CVE Evidence
Cisco DNA Spaces Connector CVE-2020-3586 Cisco OpenVuln
Cisco DNA Spaces CVE-2020-3586 Cisco OpenVuln