CVE-2020-3140

A vulnerability in the web management interface of Cisco Prime License Manager (PLM) Software could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient validation of user input on the web management interface. An attacker could exploit this vulnerability by submitting a malicious request to an affected system. An exploit could allow the attacker to gain administrative-level privileges on the system. The attacker needs a valid username to exploit this vulnerability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cisco:prime_license_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_license_manager:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:30

Type Values Removed Values Added
References () https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cisco-prime-priv-esc-HyhwdzBA - Vendor Advisory () https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cisco-prime-priv-esc-HyhwdzBA - Vendor Advisory

Information

Published : 2020-07-16 18:15

Updated : 2024-11-21 05:30


NVD link : CVE-2020-3140

Mitre link : CVE-2020-3140

CVE.ORG link : CVE-2020-3140


JSON object : View

Products Affected

cisco

  • prime_license_manager
CWE
CWE-255

Credentials Management Errors

CWE-863

Incorrect Authorization