Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-20630

Опубликовано: 10 фев. 2022
Источник: nvd
CVSS3: 4.4
CVSS2: 2.1
EPSS Низкий

Описание

A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive information in clear text. This vulnerability is due to the unsecured logging of sensitive information on an affected system. An attacker with administrative privileges could exploit this vulnerability by accessing the audit logs through the CLI. A successful exploit could allow the attacker to retrieve sensitive information that includes user credentials.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:catalyst_center:*:*:*:*:*:*:*:*
Версия от 2.1.2.0 (включая) до 2.2.2.8 (исключая)
cpe:2.3:a:cisco:catalyst_center:*:*:*:*:*:*:*:*
Версия от 2.2.3.0 (включая) до 2.2.3.4 (исключая)

EPSS

Процентиль: 18%
0.00058
Низкий

4.4 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-200
CWE-532

Связанные уязвимости

CVSS3: 4.4
github
почти 4 года назад

A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive information in clear text. This vulnerability is due to the unsecured logging of sensitive information on an affected system. An attacker with administrative privileges could exploit this vulnerability by accessing the audit logs through the CLI. A successful exploit could allow the attacker to retrieve sensitive information that includes user credentials.

CVSS3: 5.5
fstec
около 4 лет назад

Уязвимость журнала аудита системы управления сетью Cisco Digital Network Architecture (DNA) Center, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 18%
0.00058
Низкий

4.4 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-200
CWE-532