Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-20736

Опубликовано: 15 июн. 2022
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

A vulnerability in the web-based management interface of Cisco AppDynamics Controller Software could allow an unauthenticated, remote attacker to access a configuration file and the login page for an administrative console that they would not normally have authorization to access. This vulnerability is due to improper authorization checking for HTTP requests that are submitted to the affected web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected instance of AppDynamics Controller. A successful exploit could allow the attacker to access the login page for an administrative console. AppDynamics has released software updates that address this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:appdynamics_controller:*:*:*:*:*:*:*:*
Версия до 21.4.7 (исключая)

EPSS

Процентиль: 63%
0.00446
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-939
CWE-862

Связанные уязвимости

CVSS3: 5.3
github
больше 3 лет назад

A vulnerability in the web-based management interface of Cisco AppDynamics Controller Software could allow an unauthenticated, remote attacker to access a configuration file and the login page for an administrative console that they would not normally have authorization to access. This vulnerability is due to improper authorization checking for HTTP requests that are submitted to the affected web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected instance of AppDynamics Controller. A successful exploit could allow the attacker to access the login page for an administrative console. AppDynamics has released software updates that address this vulnerability.

CVSS3: 5.3
fstec
больше 4 лет назад

Уязвимость веб-интерфейса управления программного обеспечения контроллера Cisco AppDynamics Controller, позволяющая нарушителю раскрыть защищаемую информацию и повысить свои привилегии

EPSS

Процентиль: 63%
0.00446
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-939
CWE-862