CVE-2020-3382 is a critical vulnerability in the REST API of Cisco Data Center Network Manager (DCNM) that allows an unauthenticated, remote attacker to bypass authentication. This flaw stems from the use of a static encryption key shared across installations, enabling an attacker to craft a valid session token. The vulnerability carries a CVSS score of 9.8 (Critical), indicating a network-based attack with low complexity, requiring no user interaction, and resulting in complete compromise of confidentiality, integrity, and availability. A successful exploit grants administrative privileges, allowing arbitrary actions via the REST API. While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered significant community discussion and media coverage, suggesting high awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.4\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:data_center_network_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.