Improper Authentication in Cisco UCS Director Express for Big Data and Cisco UCS Director - CVE-2020-3243

 

Improper Authentication in Cisco UCS Director Express for Big Data and Cisco UCS Director - CVE-2020-3243

Published: April 16, 2020 / Updated: October 27, 2020


Vulnerability identifier: #VU26985
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3243
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to insufficient access control validation in the REST API. A remote attacker can send a specially crafted request, bypass authentication process and interact with the REST API with administrative privileges.


Affected software

Cisco UCS Director Express for Big Data
Cisco UCS Director

How to mitigate CVE-2020-3243

Install update from vendor's website.

Cisco UCS Director Express for Big Data - update to 3.7.4.0
Cisco UCS Director - update to 6.7.4.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins