Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2020-3297— Cisco Small Business Smart and Managed Switches Session Management Vulnerability

Quick assessment

Affected
Cisco Cisco Small Business 200 Series Smart Switches
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Cisco Small Business 200 Series Smart Switches等都是美国思科(Cisco)公司的产品。Cisco Small Business 200 Series Smart Switches是一款小型智能交换机设备。Cisco 350 Series Managed Switches是一款350系列管理型交换机。550X Series Stackable Managed Switches是一款550X系列管理型交换机。 多款Cisco产品中Web接口的会话管理存在授权问题漏

AI Predicted 8.6 Difficulty: Easy EPSS 3.04% · P87

Possible ATT&CK Techniques 1 AI

T1133 · External Remote Services
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2020-3297

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco Small Business Smart and Managed Switches Session Management Vulnerability
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in session management for the web-based interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to defeat authentication protections and gain unauthorized access to the management interface. The attacker could obtain the privileges of the highjacked session account, which could include administrator privileges on the device. The vulnerability is due to the use of weak entropy generation for session identifier values. An attacker could exploit this vulnerability to determine a current session identifier through brute force and reuse that session identifier to take over an ongoing session. In this way, an attacker could take actions within the management interface with privileges up to the level of the administrative user.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
多款Cisco产品授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco Small Business 200 Series Smart Switches等都是美国思科(Cisco)公司的产品。Cisco Small Business 200 Series Smart Switches是一款小型智能交换机设备。Cisco 350 Series Managed Switches是一款350系列管理型交换机。550X Series Stackable Managed Switches是一款550X系列管理型交换机。 多款Cisco产品中Web接口的会话管理存在授权问题漏
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Cisco Cisco Small Business 200 Series Smart Switches n/a -

II. Public POCs for CVE-2020-3297

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-3297

请登录查看更多情报信息。

Vendor Advisories for CVE-2020-3297 (1)

Same Patch Batch · Cisco · 2020-07-02 · 5 CVEs total

CVE-2020-3282 Cisco Unified Communications Products Cross-Site Scripting Vulnerability
CVE-2020-3402 Cisco Unified Customer Voice Portal Information Disclosure Vulnerability
CVE-2020-3391 Cisco Digital Network Architecture Center Information Disclosure Vulnerability
CVE-2020-3340 Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities

IV. Related Vulnerabilities

V. Comments for CVE-2020-3297

No comments yet


Leave a comment