Description
A vulnerability in the web-based management interface of Cisco Mobility Express Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user with an active session on an affected device to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions, including modifying the configuration, with the privilege level of the user.
Published: 2020-04-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-24532 A vulnerability in the web-based management interface of Cisco Mobility Express Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user with an active session on an affected device to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions, including modifying the configuration, with the privilege level of the user.
History

Fri, 15 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco 6300 Series Access Points 6300 Series Access Points Firmware Aironet 1542d Aironet 1542d Firmware Aironet 1542i Aironet 1542i Firmware Aironet 1562d Aironet 1562d Firmware Aironet 1562e Aironet 1562e Firmware Aironet 1562i Aironet 1562i Firmware Aironet 1815 Aironet 1815 Firmware Aironet 1830 Aironet 1830 Firmware Aironet 1840 Aironet 1840 Firmware Aironet 1850 Aironet 1850 Firmware Aironet 2800e Aironet 2800e Firmware Aironet 2800i Aironet 2800i Firmware Aironet 3800e Aironet 3800e Firmware Aironet 3800i Aironet 3800i Firmware Aironet 3800p Aironet 3800p Firmware Aironet 4800 Aironet 4800 Firmware Catalyst Iw6300 Catalyst Iw6300 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-15T17:28:53.825Z

Reserved: 2019-12-12T00:00:00.000Z

Link: CVE-2020-3261

cve-icon Vulnrichment

Updated: 2024-08-04T07:30:57.614Z

cve-icon NVD

Status : Modified

Published: 2020-04-15T21:15:36.060

Modified: 2024-11-21T05:30:40.760

Link: CVE-2020-3261

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses