First published: Wed Nov 18 2020(Updated: )
A vulnerability in Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive database information on an affected device. The vulnerability is due to the absence of authentication for sensitive information. An attacker could exploit this vulnerability by sending crafted curl commands to an affected device. A successful exploit could allow the attacker to view sensitive database information on the affected device.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IoT Field Network Director | <4.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-26076 has been rated as high severity due to the potential unauthorized access to sensitive database information.
To mitigate CVE-2020-26076, upgrade to a version of Cisco IoT Field Network Director that is 4.6.1 or later.
CVE-2020-26076 affects Cisco IoT Field Network Director versions prior to 4.6.1.
Yes, CVE-2020-26076 can be exploited by an unauthenticated remote attacker.
Exploitation of CVE-2020-26076 allows attackers to view sensitive database information on the affected device.