#VU48546 Missing Authentication for Critical Function in Cisco IoT Field Network Director - CVE-2020-3531
Published: November 18, 2020 / Updated: November 19, 2020
Cisco IoT Field Network Director
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the affected system does not properly authenticate API calls. A remote attacker can obtain a cross-site request forgery (CSRF) token, then use the token with REST API requests, access the back-end database of the affected device and read, alter, or drop information.