CVE-2020-3521: Cisco Data Center Network Manager Read File Path Traversal Vulnerability
A vulnerability in a specific REST API of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability is due to insufficient validation of user-supplied input to the API. An attacker with a low-privileged account could exploit this vulnerability by sending a crafted request to the API. A successful exploit could allow the attacker to read arbitrary files on the affected system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-3521?
CVE-2020-3521 is a vulnerability in Cisco Data Center Network Manager (DCNM) Software that allows an authenticated, remote attacker to conduct directory traversal attacks.
How does CVE-2020-3521 affect the Cisco Data Center Network Manager (DCNM) software?
CVE-2020-3521 affects Cisco Data Center Network Manager (DCNM) Software versions up to 11.4(1).
What is the severity of CVE-2020-3521?
The severity of CVE-2020-3521 is medium with a CVSS score of 6.5.
How can an attacker exploit CVE-2020-3521?
An attacker can exploit CVE-2020-3521 by exploiting a specific REST API in Cisco Data Center Network Manager (DCNM) Software to conduct directory traversal attacks.
Is there a fix for CVE-2020-3521?
Yes, Cisco has released a security advisory with guidance on how to mitigate this vulnerability.