Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Nicholas Buckingham

Pesquisador deVerizon
#26804de 53,639
9.4CVSS total
Vulnerabilidades · 1
PT-2023-3493
9.4
2023-07-13
Cisco · Cisco Sd-Wan Vmanage · CVE-2023-20214
**Name of the Vulnerable Software and Affected Versions** Cisco SD-WAN vManage software (affected versions not specified) **Description** A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance. This vulnerability is due to insufficient request validation when using the REST API feature. An attacker could exploit this vulnerability by sending a crafted API request to an affected vManage instance. A successful exploit could allow the attacker to retrieve information from and send information to the configuration of the affected Cisco vManage instance. This vulnerability only affects the REST API and does not affect the web-based management interface or the CLI. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.