Improper access control in Cisco Systems, Inc products - CVE-2020-3329
Published: May 7, 2020
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to incorrect allocation of the enable/disable action button under the role-based access control code. A remote user with read-only permission can update the roles of other users to disable them, including administrative users.
Affected software
Cisco UCS Director
Cisco UCS Director Express for Big Data
How to mitigate CVE-2020-3329
Cisco UCS Director - update to 6.7.4.0
Cisco UCS Director Express for Big Data - update to 3.7.4.0