CVE-2020-3391

MEDIUM

Cisco DNA Center < 1.2.10 Authenticated Sensitive Information Exposure via Cleartext Credential Storage

Title source: llm
STIX 2.1

Description

A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to insecure storage of certain unencrypted credentials on an affected device. An attacker could exploit this vulnerability by viewing the network device configuration and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to discover and manage network devices.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0020
EPSS Percentile 41.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-522 CWE-200
Status published
Products (1)
cisco/digital_network_architecture_center < 1.2.10
Published Jul 02, 2020
Tracked Since Feb 18, 2026