CVE-2020-3384 describes a command injection vulnerability in specific REST API endpoints of Cisco Data Center Network Manager (DCNM). This flaw allows an authenticated, remote attacker to inject arbitrary commands on the underlying operating system due to insufficient input validation. The vulnerability carries a CVSS score of 8.2 (HIGH), indicating a high severity risk where an attacker could achieve significant impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation (KEV listed as No) and no public exploit code (Metasploit, Nuclei, ExploitDB all show None), the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.4\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:data_center_network_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.