PT-2023-17423 · Cisco · Cisco Catalyst Sd-Wan Manager
Heba Farahat
+1
·
Published
2023-10-18
·
Updated
2024-01-25
·
CVE-2023-20261
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Catalyst SD-WAN Manager (affected versions not specified)
Description
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affected system. This issue is due to improper validation of parameters sent to the web UI. An attacker could exploit this by logging in to Cisco Catalyst SD-WAN Manager and issuing crafted requests using the web UI, potentially obtaining arbitrary files from the underlying Linux file system of an affected system. The attacker must be an authenticated user to exploit this vulnerability.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Catalyst Sd-Wan Manager