CVE-2020-3411

HIGH

Cisco Catalyst Center 1.3-1.3.1.3 - Unauthenticated Sensitive Information Disclosure via Authentication Token Handling

Title source: llm
STIX 2.1

Description

A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access to sensitive information on an affected system. The vulnerability is due to improper handling of authentication tokens by the affected software. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker access to sensitive device information, which includes configuration files.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0029
EPSS Percentile 52.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-287 CWE-200
Status published
Products (1)
cisco/catalyst_center 1.3 - 1.3.1.4
Published Aug 17, 2020
Tracked Since Feb 18, 2026