PT-2023-17423 · Cisco · Cisco Catalyst Sd-Wan Manager

Heba Farahat

+1

·

Publicado

2023-10-18

·

Atualizado

2024-01-25

·

CVE-2023-20261

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Catalyst SD-WAN Manager (affected versions not specified)
Description A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affected system. This issue is due to improper validation of parameters sent to the web UI. An attacker could exploit this by logging in to Cisco Catalyst SD-WAN Manager and issuing crafted requests using the web UI, potentially obtaining arbitrary files from the underlying Linux file system of an affected system. The attacker must be an authenticated user to exploit this vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-20261

Produtos afetados

Cisco Catalyst Sd-Wan Manager