CVE-2020-3261 describes a Cross-Site Request Forgery (CSRF) vulnerability in the web-based management interface of Cisco Mobility Express Software. This flaw stems from insufficient CSRF protections, allowing an unauthenticated, remote attacker to potentially manipulate an affected system. The vulnerability has a CVSS score of 6.5 (Medium), indicating it can be exploited over the network with low attack complexity, requiring user interaction. A successful attack could enable an attacker to perform arbitrary actions, including configuration modifications, with the privileges of the targeted user. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0, < 8.8.130.0CPE matchmatch criteria | cpe:2.3:o:cisco:aironet_1542i_firmware:*:*:*:*:*:*:*:* | ||
8.10\(1.255\)CPE matchmatch criteria | cpe:2.3:o:cisco:aironet_1542i_firmware:8.10\(1.255\):*:*:*:*:*:*:* | ||
>= 8.0, < 8.8.130.0CPE matchmatch criteria | cpe:2.3:o:cisco:aironet_1542d_firmware:*:*:*:*:*:*:*:* | ||
8.10\(1.255\)CPE matchmatch criteria | cpe:2.3:o:cisco:aironet_1542d_firmware:8.10\(1.255\):*:*:*:*:*:*:* | ||
>= 8.0, < 8.8.130.0CPE matchmatch criteria | cpe:2.3:o:cisco:aironet_1562i_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.