PT-2022-2286 · Cisco · Cisco Dna Center

David Yarashus

·

Published

2022-02-02

·

Updated

2025-07-23

·

CVE-2022-20630

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco DNA Center (affected versions not specified)
Description A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive information in clear text. This issue is due to the unsecured logging of sensitive information on an affected system. An attacker with administrative privileges could exploit this by accessing the audit logs through the CLI, potentially retrieving sensitive information, including user credentials.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Insertion into Log File

Weakness Enumeration

Related Identifiers

BDU:2022-02470
CVE-2022-20630

Affected Products

Cisco Dna Center