Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rjvr-rwwj-qxq2

Опубликовано: 27 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could allow an unauthenticated, remote attacker to gain unauthorized access to the application as an arbitrary user.

This vulnerability is due to improper authentication checks for SAML APIs. An attacker could exploit this vulnerability by sending requests directly to the SAML API. A successful exploit could allow the attacker to generate an authorization token sufficient to gain access to the application.

A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could allow an unauthenticated, remote attacker to gain unauthorized access to the application as an arbitrary user.

This vulnerability is due to improper authentication checks for SAML APIs. An attacker could exploit this vulnerability by sending requests directly to the SAML API. A successful exploit could allow the attacker to generate an authorization token sufficient to gain access to the application.

EPSS

Процентиль: 77%
0.01011
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-862

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could allow an unauthenticated, remote attacker to gain unauthorized access to the application as an arbitrary user. This vulnerability is due to improper authentication checks for SAML APIs. An attacker could exploit this vulnerability by sending requests directly to the SAML API. A successful exploit could allow the attacker to generate an authorization token sufficient to gain access to the application.

CVSS3: 9.8
fstec
больше 2 лет назад

Уязвимость прикладного программного интерфейса модуля единого входа в приложения (SAML) централизованной системы управления сетью Cisco Catalyst SD-WAN Manager, позволяющая нарушителю получить доступ к приложению

EPSS

Процентиль: 77%
0.01011
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-862