cisco data-center-network-manager CVE-2020-3380 is a vulnerability in Cisco Data Center Network Manager
Published on July 16, 2020

Cisco Data Center Network Manager Privilege Escalation Vulnerability
A vulnerability in the CLI of Cisco Data Center Network Manager (DCNM) could allow an authenticated, local attacker to elevate privileges to root and execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient restrictions during the execution of an affected CLI command. An attacker could exploit this vulnerability by authenticating as the fmserver user and submitting malicious input to a specific command. A successful exploit could allow the attacker to elevate privileges to root and execute arbitrary commands on the underlying operating system.

Vendor Advisory NVD

Weakness Type

What is an Argument Injection Vulnerability?

The software constructs a string for a command to executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

CVE-2020-3380 has been classified to as an Argument Injection vulnerability or weakness.


Products Associated with CVE-2020-3380

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2020-3380 are published in Cisco Data Center Network Manager:

 

Affected Versions

Cisco Data Center Network Manager Version n/a is affected by CVE-2020-3380

Exploit Probability

EPSS
0.20%
Percentile
41.51%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.