Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-723j-vwr2-6865

Опубликовано: 23 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text. The attacker must have valid low-privileged user credentials. This vulnerability is due to improper role-based access control (RBAC) with the integration of PnP. An attacker could exploit this vulnerability by authenticating to the device and sending a query to an internal API. A successful exploit could allow the attacker to view sensitive information in clear text, which could include configuration files.

A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text. The attacker must have valid low-privileged user credentials. This vulnerability is due to improper role-based access control (RBAC) with the integration of PnP. An attacker could exploit this vulnerability by authenticating to the device and sending a query to an internal API. A successful exploit could allow the attacker to view sensitive information in clear text, which could include configuration files.

EPSS

Процентиль: 32%
0.00127
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-312
CWE-555

Связанные уязвимости

CVSS3: 4.3
nvd
почти 3 года назад

A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text. The attacker must have valid low-privileged user credentials. This vulnerability is due to improper role-based access control (RBAC) with the integration of PnP. An attacker could exploit this vulnerability by authenticating to the device and sending a query to an internal API. A successful exploit could allow the attacker to view sensitive information in clear text, which could include configuration files.

CVSS3: 4.3
fstec
почти 3 года назад

Уязвимость реализации технологии для быстрого определения и конфигурирования устройств Cisco Network Plug-and-Play (PnP) центра управления сетью Cisco DNA Center, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 32%
0.00127
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-312
CWE-555