CVE-2020-3392 - CVE House
Back to Database
Status published High CVE-2020-3392

Cisco IoT Field Network Director Missing API Authentication Vulnerability

Vulnerability Description

A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on an affected system. The vulnerability exists because the affected software does not properly authenticate API calls. An attacker could exploit this vulnerability by sending API requests to an affected system. A successful exploit could allow the attacker to view sensitive information on the affected system, including information about the devices that the system manages, without authentication.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-3392

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco IoT Field Network Director (IoT-FND)
Vulnerable Versions:
Unknown

Timeline

Official Publish: November 18th, 2020
Last Modified: November 13th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)