#VU45995 Improper Authentication in Cisco Connected Mobile Experiences - CVE-2020-3151

 

#VU45995 Improper Authentication in Cisco Connected Mobile Experiences - CVE-2020-3151

Published: August 25, 2020


Vulnerability identifier: #VU45995
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-3151
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Cisco Connected Mobile Experiences
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a local user to bypass authentication process.

The vulnerability exists due to insufficient security mechanisms in the restricted shell implementation in the CLI. A local administrator can send specially crafted commands to the CLI, bypass authentication process and gain unauthorized access to the application.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links