CVE-2020-3520

MEDIUM

Cisco Data Center Network Manager < 11.4(1) - Authenticated Sensitive Information Exposure via Local Filesystem Access

Title source: llm
STIX 2.1

Description

A vulnerability in Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, local attacker to obtain confidential information from an affected device. The vulnerability is due to insufficient protection of confidential information on an affected device. An attacker at any privilege level could exploit this vulnerability by accessing local filesystems and extracting sensitive information from them. A successful exploit could allow the attacker to view sensitive data, which they could use to elevate their privilege.

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0006
EPSS Percentile 18.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
cisco/data_center_network_manager < 11.4\(1\)
Published Aug 26, 2020
Tracked Since Feb 18, 2026