← Back

CVE-2020-26080

nvd nist
Published: Nov 18, 2020Modified: Nov 21, 2024

JSON object

Loading...
4.1
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N
Exploitability: 2.3 / Impact: 1.4
Source: NVD

Description

A vulnerability in the user management functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to manage user information for users in different domains on an affected system. The vulnerability is due to improper domain access control. An attacker could exploit this vulnerability by manipulating JSON payloads to target different domains on an affected system. A successful exploit could allow the attacker to manage user information for users in different domains on an affected system.

Affected (1)

1 product
Iot Field Network Director
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 4.6.1

Timeline

No history available yet.