← Vulnerability feed

Vulnerability record · CVE-2020-3281 · published 3 June 2020

CVE-2020-3281: Cisco digital network architecture center sensitive information in log file vulnerability

Cisco · Digital Network Architecture Center

A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to discover and manage network devices.

8.8 CVSS 3.1 High EPSS 1.0% · top 37.2% CWE-532 · Sensitive information in log file
8.8CVSS 3.1 base score, v2 4.0
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to discover and manage network devices.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-3281 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2018-0222Cisco digital network architecture center hard-coded credentials vulnerabilityA vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to log in to an affected system by…EPSS 3.6%10.0CVE-2018-0268Cisco digital network architecture center vulnerabilityA vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attac…EPSS 5.0%9.8CVE-2018-15386Cisco digital network architecture center vulnerabilityA vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and have …EPSS 3.4%9.8CVE-2018-0448Cisco digital network architecture center inadequate encryption strength vulnerabilityA vulnerability in the identity management service of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker…EPSS 2.1%9.8CVE-2018-0271Cisco digital network architecture center improper authentication vulnerabilityA vulnerability in the API gateway of the Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass a…EPSS 2.5%9.3CVE-2019-1848Cisco digital network architecture center exposure of resource to wrong sphere vulnerabilityA vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to bypass authentication and acc…EPSS 0.73%7.5CVE-2019-1675Cisco aironet active sensor hard-coded credentials vulnerabilityA vulnerability in the default configuration of the Cisco Aironet Active Sensor could allow an unauthenticated, remote attacker to restart the sensor…EPSS 2.6%7.5CVE-2018-5390Linux kernel TCP out-of-order queue processing denial of serviceLinux kernel versions 4.9 and later can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incomi…EPSS 74%analysed

Source: NIST National Vulnerability Database (record CVE-2020-3281), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.