VDB

CVE-2020-3297

CVE-2020-3297 PUBLISHED CVSS 8.100000381469727 HIGH

A vulnerability in session management for the web-based interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to defeat authentication protections and gain unauthorized access to the management interface. The attacker could obtain the privileges of the highjacked session account, which could include administrator privileges on the device. The vulnerability is due to the use of weak entropy generation for session identifier values. An attacker could exploit this vulnerability to determine a current session identifier through brute force and reuse that session identifier to take over an ongoing session. In this way, an attacker could take actions within the management interface with privileges up to the level of the administrative user.

EPSS 5.41% · 90.3th percentile

Risk Scores

CVSS 3.0
8.100000381469727
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
5.41%
90.3th percentile

Affected Products

VendorProductVersions
ciscosf300-08_firmware
ciscosg250x-24_firmware0
ciscosf350-48mp_firmware0
ciscosf500-24p_firmware
ciscosg200-26p_firmware
ciscosg250-26hp_firmware0
ciscosf200e-48p_firmware
ciscosf302-08p_firmware
ciscosf500-24_firmware
ciscosf250-24_firmware0
ciscosg350xg-2f10_firmware0
CiscoN/A
ciscosg300-52_firmware
ciscosf550x-48p_firmware0
ciscosf300-24_firmware
ciscosg500x-24p_firmware
ciscosg500x-48_firmware
ciscosg550x-48_firmware0
ciscosg250-10p_firmware0
ciscosg250x-48_firmware0

…and 101 more

Timeline

  • Jul 2, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›