Information disclosure in Cisco UCS Director - CVE-2020-3242

 

Information disclosure in Cisco UCS Director - CVE-2020-3242

Published: June 18, 2020


Vulnerability identifier: #VU29145
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3242
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to confidential information is returned as part of an API response. A remote administrator can send a specially crafted request and obtain the API key of another user, allowing him to impersonate the account of that user on the affected device


Affected software

Cisco UCS Director

How to mitigate CVE-2020-3242

Install updates from vendor's website.

Cisco UCS Director - update to 6.7.4.0

External References

Related Security Bulletins