First published: Wed Nov 18 2020(Updated: )
A vulnerability in the web-based management interface of Cisco DNA Spaces Connector could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient validation of user-supplied input in the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on the underling operating system with privileges of the web-based management application, which is running as a restricted user. This could result in changes being made to pages served by the web-based management application impacting the integrity or availability of the web-based management application.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco DNA Spaces: Connector | <=2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3586 is a vulnerability in the web-based management interface of Cisco DNA Spaces Connector that could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device.
The severity of CVE-2020-3586 is critical with a CVSS score of 9.8.
CVE-2020-3586 affects Cisco DNA Spaces Connector by allowing an unauthenticated, remote attacker to execute arbitrary commands on an affected device.
To fix CVE-2020-3586, it is recommended to apply the necessary updates or patches provided by Cisco.
More information about CVE-2020-3586 can be found on the Cisco Security Advisory website.