Unrated severityNVD Advisory· Published Jun 3, 2020· Updated Nov 15, 2024
Cisco Application Services Engine Software Unauthenticated Event Policies Update Vulnerability
CVE-2020-3333
Description
A vulnerability in the API of Cisco Application Services Engine Software could allow an unauthenticated, remote attacker to update event policies on an affected device. The vulnerability is due to insufficient authentication of users who modify policies on an affected device. An attacker could exploit this vulnerability by crafting a malicious HTTP request to contact an affected device. A successful exploit could allow the attacker to update event policies on the affected device.
Affected products
1- Range: n/a
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-APIC-EPU-F8y5kUOPmitrevendor-advisoryx_refsource_CISCO
News mentions
0No linked articles in our index yet.