CVE-2020-3335

MEDIUM

Cisco Application Services Engine Software - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attacker to read sensitive information of other users on an affected device. The vulnerability is due to insufficient authorization limitations. An attacker could exploit this vulnerability by logging in to an affected device locally with valid credentials. A successful exploit could allow the attacker to read the sensitive information of other users on the affected device.

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0004
EPSS Percentile 14.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306 CWE-863
Status published
Products (2)
cisco/application_policy_infrastructure_controller 1.1\(0c\)
cisco/application_services_engine < 1.1.2.20
Published Jun 03, 2020
Tracked Since Feb 18, 2026