CVE-2020-26079
MEDIUMCisco IoT FND - Info Disclosure
Title source: llmDescription
A vulnerability in the web UI of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to obtain hashes of user passwords on an affected device. The vulnerability is due to insufficient protection of user credentials. An attacker could exploit this vulnerability by logging in as an administrative user and crafting a call for user information. A successful exploit could allow the attacker to obtain hashes of user passwords on an affected device.
Scores
CVSS v3
4.9
EPSS
0.0017
EPSS Percentile
37.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-522
CWE-256
Status
published
Affected Products (1)
cisco/iot_field_network_director
< 4.6.1
Timeline
Published
Nov 18, 2020
Tracked Since
Feb 18, 2026