CVE-2020-3139 is a medium-severity vulnerability affecting Cisco Application Policy Infrastructure Controller (APIC) releases prior to 4.2(3j). It allows an unauthenticated, remote attacker to bypass configured deny rules for specific IP ports on the out-of-band (OOB) management interface due to a programming logic error in IP table entries. The vulnerability has a CVSS score of 5.3 (MEDIUM) with a low impact on integrity (I:L) and no impact on confidentiality or availability, as the attacker cannot control device configuration. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.2\(3j\)CPE matchmatch criteria | cpe:2.3:a:cisco:application_policy_infrastructure_controller:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.