Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-3448— Cisco Cyber Vision Center Software Access Control Bypass Vulnerability

EPSS 0.57% · P69
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2020-3448

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco Cyber Vision Center Software Access Control Bypass Vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in an access control mechanism of Cisco Cyber Vision Center Software could allow an unauthenticated, remote attacker to bypass authentication and access internal services that are running on an affected device. The vulnerability is due to insufficient enforcement of access control in the software. An attacker could exploit this vulnerability by directly accessing the internal services of an affected device. A successful exploit could allow an attacker to impact monitoring of sensors that are managed by the software.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
访问控制不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco Cyber Vision Center Software 访问控制错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco Cyber Vision Center Software是美国思科(Cisco)公司的一套工业控制系统(ICS)监控解决方案。该产品支持动态资产清单、网络实时监控等功能。 Cisco Cyber Vision Center Software 3.0.4之前版本和3.1.0之前版本中的访问控制机制存在访问控制错误漏洞。远程攻击者可通过直接访问内部服务利用该漏洞影响传感器的监测。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
CiscoCisco Cyber Vision n/a -

II. Public POCs for CVE-2020-3448

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-3448

登录查看更多情报信息。

Same Patch Batch · Cisco · 2020-08-17 · 17 CVEs total

CVE-2020-34337.8 HIGHCisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
CVE-2020-35006.8 MEDIUMCisco StarOS IPv6 Denial of Service Vulnerability
CVE-2020-34636.1 MEDIUMCisco Webex Meetings Reflected Cross-Site Scripting Vulnerability
CVE-2020-33466.1 MEDIUMCisco Unified Communications Manager Cross-Site Scripting Vulnerability
CVE-2020-34475.5 MEDIUMCisco Email Security Appliance and Cisco Content Security Management Appliance Information
CVE-2020-34355.5 MEDIUMCisco AnyConnect Secure Mobility Client for Windows Profile Modification Vulnerability
CVE-2020-34345.5 MEDIUMCisco AnyConnect Secure Mobility Client for Windows Denial of Service Vulnerability
CVE-2020-34725.0 MEDIUMCisco Webex Meetings User Email Address Information Disclosure Vulnerability
CVE-2020-34644.8 MEDIUMCisco UCS Director Stored Cross-Site Scripting Vulnerability
CVE-2020-34494.3 MEDIUMCisco IOS XR Software Additional Paths Denial of Service Vulnerability
CVE-2020-34134.3 MEDIUMCisco Webex Meetings Scheduled Meeting Template Deletion Vulnerability
CVE-2020-34124.3 MEDIUMCisco Webex Meetings Scheduled Meeting Template Creation Vulnerability
CVE-2020-35024.1 MEDIUMCisco Webex Meetings Desktop App Information Disclosure Vulnerabilities
CVE-2020-35014.1 MEDIUMCisco Webex Meetings Desktop App Information Disclosure Vulnerabilities
CVE-2020-3411Cisco DNA Center Information Disclosure Vulnerability
CVE-2020-3363Cisco Small Business Smart and Managed Switches Denial of Service Vulnerability

IV. Related Vulnerabilities

V. Comments for CVE-2020-3448

No comments yet


Leave a comment