CVE-2020-3389 is a vulnerability in the installation component of Cisco Hyperflex HX-Series Software that allows an authenticated, local attacker to retrieve the installation password. This is due to sensitive information being stored in clear text. With a CVSS score of 4.4 (MEDIUM), exploitation requires high privileges and local access, but a successful attack grants full confidentiality of the password. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0\(2a\)CPE matchmatch criteria | cpe:2.3:a:cisco:hyperflex_hx-series_software:4.0\(2a\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.