Improper access control in Cisco IoT Field Network Director - CVE-2020-26072
Published: November 18, 2020 / Updated: November 19, 2020
Cisco IoT Field Network Director
Detailed vulnerability description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the SOAP API. A remote administrator can send SOAP API requests to access and modify information on devices that belong to a different domain.