#VU29249 Improper access control in Cisco Smart Software Manager On-Prem - CVE-2020-3245
Published: June 25, 2020
Cisco Smart Software Manager On-Prem
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the web application. A remote attacker can send a specially crafted HTTP request, bypass implemented security restrictions and add user accounts to the configuration of an affected device.