PT-2023-17423 · Cisco · Cisco Catalyst Sd-Wan Manager

Heba Farahat

+1

·

Published

2023-10-18

·

Updated

2024-01-25

·

CVE-2023-20261

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Catalyst SD-WAN Manager (affected versions not specified)
Description A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affected system. This issue is due to improper validation of parameters sent to the web UI. An attacker could exploit this by logging in to Cisco Catalyst SD-WAN Manager and issuing crafted requests using the web UI, potentially obtaining arbitrary files from the underlying Linux file system of an affected system. The attacker must be an authenticated user to exploit this vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2023-20261

Affected Products

Cisco Catalyst Sd-Wan Manager