CVE-2020-3252: Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-3252?
CVE-2020-3252 is a vulnerability in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data.
What is the severity of CVE-2020-3252?
CVE-2020-3252 has a severity level of critical.
How can a remote attacker exploit CVE-2020-3252?
A remote attacker can exploit CVE-2020-3252 to bypass authentication or conduct directory traversal attacks on an affected device.
Which versions of Cisco UCS Director and Cisco UCS Director Express for Big Data are affected by CVE-2020-3252?
Cisco UCS Director versions 6.0.0.0 to 6.7.3.0 and Cisco UCS Director Express for Big Data version 3.7.3.0 are affected by CVE-2020-3252.
Where can I find more information about CVE-2020-3252?
You can find more information about CVE-2020-3252 in the Cisco Security Advisory: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucsd-mult-vulns-UNfpdW4E