CVE-2020-3586 is a critical vulnerability affecting Cisco DNA Spaces Connector, allowing unauthenticated, remote attackers to execute arbitrary commands due to insufficient input validation in its web-based management interface. With a CVSS score of 9.8, this flaw presents a low-complexity attack vector (AV:N/AC:L) that can lead to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H) of the affected system, albeit with restricted user privileges. While not currently listed in CISA's KEV catalog and lacking public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.2CPE matchmatch criteria | cpe:2.3:a:cisco:dna_spaces\:_connector:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.