PT-2022-5297 · Cisco · Cisco Smart Software Manager On-Prem

Published

2022-10-05

·

Updated

2025-07-31

·

CVE-2022-20939

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Smart Software Manager On-Prem (affected versions not specified)
Description A vulnerability in the web-based management interface could allow an authenticated, remote attacker to elevate privileges on an affected system. This issue is due to inadequate protection of sensitive user information. An attacker could exploit this by accessing certain logs, potentially allowing them to use the obtained information to elevate privileges to System Admin.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2022-06582
CVE-2022-20939

Affected Products

Cisco Smart Software Manager On-Prem