PT-2023-3493 · Cisco · Cisco Sd-Wan Vmanage

Nicholas Buckingham

·

Published

2023-07-13

·

Updated

2024-01-25

·

CVE-2023-20214

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Cisco SD-WAN vManage software (affected versions not specified)
Description A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance. This vulnerability is due to insufficient request validation when using the REST API feature. An attacker could exploit this vulnerability by sending a crafted API request to an affected vManage instance. A successful exploit could allow the attacker to retrieve information from and send information to the configuration of the affected Cisco vManage instance. This vulnerability only affects the REST API and does not affect the web-based management interface or the CLI.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2023-03693
CVE-2023-20214

Affected Products

Cisco Sd-Wan Vmanage