PT-2023-2109 · Cisco · Cisco Unified Intelligence Center

Kareem Mohamed

·

Published

2023-03-01

·

Updated

2023-03-10

·

CVE-2023-20061

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Unified Intelligence Center (affected versions not specified)
Description The issue is related to the implementation of the application programming interface in the Cisco Unified Intelligence Center reporting tool, which lacks protection of service data. This could allow a remote attacker to gain unauthorized access to the device. An authenticated, remote attacker may collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exposure of Resource to Wrong Sphere

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2023-01846
CVE-2023-20061

Affected Products

Cisco Unified Intelligence Center