CVE-2020-8349
An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ optional REST API management interface. This interface is disabled by default and not vulnerable unless enabled. When enabled, it is only vulnerable where attached to a VRF and as allowed by defined ACLs. Lenovo strongly recommends upgrading to a non-vulnerable CNOS release. Where not possible, Lenovo recommends disabling the REST API management interface or restricting access to the management VRF and further limiting access to authorized management stations via ACL.
Published:Oct 14, 2020
Last Modified:Nov 21, 2024
EPS:Oct 14, 2020
EPSS Score:0.02622
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Lenovo
Product
Cloud Networking Operating System
Lenovo
Cloud Networking Operating System
Vendor
Lenovo
Product
Rackswitch G8272
Lenovo
Rackswitch G8272
Vendor
Lenovo
Product
Rackswitch G8296
Lenovo
Rackswitch G8296
Vendor
Lenovo
Product
Rackswitch G8332
Lenovo
Rackswitch G8332
Vendor
Lenovo
Product
Rackswitch Ne0152t
Lenovo
Rackswitch Ne0152t
Vendor
Lenovo
Product
Rackswitch Ne10032
Lenovo
Rackswitch Ne10032
Vendor
Lenovo
Product
Rackswitch Ne1032
Lenovo
Rackswitch Ne1032
Vendor
Lenovo
Product
Rackswitch Ne1032t
Lenovo
Rackswitch Ne1032t
Vendor
Lenovo
Product
Rackswitch Ne1072t
Lenovo
Rackswitch Ne1072t
Vendor
Lenovo
Product
Rackswitch Ne2572
Lenovo
Rackswitch Ne2572
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
