CVE-2020-26072

Description

A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify information on devices that belong to a different domain. The vulnerability is due to insufficient authorization in the SOAP API. An attacker could exploit this vulnerability by sending SOAP API requests to affected devices for devices that are outside their authorized domain. A successful exploit could allow the attacker to access and modify information on devices that belong to a different domain.

Risk Information

Base Score
8.7
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
EPSS Score
Exploitation Probability
0.228

Associated Vulnerability

VulnerabilityOS Platform
Cisco IoT Field Network Director SOAP API Authorization Bypass Vulnerability For Network Level ServiceNCM
Improper Privilege Management Vulnerability (CVE-2020-26072)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1705206Security Update for Network Level Service 4.6.1(22)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234